> Markdown version of [/jobs/ext/3243140-senior-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/3243140-senior-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Engineer - **Company:** Scottish Government - **Location:** Glasgow, UK - **Experience:** Expert - **Salary:** £48,000.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Software as a Service, Cloud Computing Security, Cloud Engineering, Encodings, Cyber Security, Continuous Delivery, Continuous Integration, DevOps, Infrastructure as a Service (IaaS), Identity and Access Management, Key Management, Platform as a Service (PAAS), Public Key Infrastructure, Secure Coding, Security Software, Software Vulnerability Management, Policy as Code, Data Logging, Infrastructure as Code (IaC), Cloudformation, Deployment Automation, Terraform - **Published:** September 23, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=796904d0d747d008 ## About the Role * Experience implementing cloud native security controls such as IAM, encryption, key management, logging, and monitoring. * Experience embedding security across the full delivery lifecycle, from early design through to live operations. Experience creating or implementing automated security controls and assurance, e.g. policy as code, configuration compliance, or security monitoring rules utilising IaC Tooling. * ## Description Social Security Scotland is seeking a Senior Cyber Security Engineer to help secure the cloud platforms that deliver vital public services. This is a key role in a cloud first organisation, working to ensure solutions are secure by design, resilient, and compliant. The Senior Cyber Security Engineer leads the design, implementation, and assurance of cyber security controls across cloud platforms, applications, and infrastructure. You will translate security policy and risk into practical cloud security solutions, working closely with Architecture, Cloud Engineering, DevOps, and Product teams. Acting as a technical authority, you will provide hands-on expertise, assurance, and risk-based guidance, embedding security throughout the delivery lifecycle. The Cyber Security Engineer builds, develops, and configures tooling and processes to be secure. They build tooling to support pre-commit, Continuous Integration, Continuous Deployment through to production. They have experience of operating systems, Networking, PKI and Cloud Security tools. They build Secure Configuration Management using Infrastructure as Code. * Identify, design and develop cyber security solutions across a wide variety of applications and infrastructure * Lead the implementation of cyber security policy and standards * Provide senior cyber security consultancy services (from risk assessments and audits to strategy development) across a variety of technology projects * Engage with the Technology Architecture team and support the design of technology solutions and architecture for a variety of projects and programmes * Engage with a broad range of internal and external stakeholders, providing cyber security assurance and managing the change process for the implementation of cyber security strategy, standards and solutions., This role is aligned to Senior Cyber Security Engineer within the Government Digital and Data Profession. Please review the following to understand the skill expectations: Cyber Security Engineer - Cyber security: operations - gov.scot These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage. How to Apply Apply online, providing a CV and Supporting Statement (of no more than 750 words) which provides evidence of how you meet the Experience and Behaviours listed in the Success Profiles above. Artificial Intelligence (AI) tools can be used to support your application, but all statements and examples provided must be truthful, factually accurate and taken directly from your own experience. Where plagiarism has been identified (presenting the ideas and experiences of others, or generated by artificial intelligence, and presented as your own) applications will be withdrawn and internal candidates may be subject to disciplinary action. Please see our candidate guidance for more information on acceptable and unacceptable uses of AI in recruitment. Should a large number of applications be received, an initial sift may be conducted using the CV and Supporting Statement on the first 'Experience' criteria. Candidates who pass the initial sift will have their applications fully assessed. Please note, there may be a telephone interview prior to the final interview stage. Successful candidates will be invited to an interview which will assess the Experience and Behaviours, and a technical assessment comprising a short presentation which will assess the Technical Skills. Full details of the interview and assessment process will be shared with shortlisted candidates once the sift has been completed. We aim to provide feedback on request. However, if we receive a large number of applications it may not be possible for us to provide specific feedback on your application. We will provide feedback on request to candidates who attend an interview/assessment., Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us. Security Checks Successful candidates must complete the Baseline Personnel Security Standard (BPSS), before they can be appointed. BPSS is comprised of four main pre-employment checks - Identity, Right to work, Employment History and a Criminal Record check (unspent convictions). Due to the nature of this post, the successful candidate is also required to clear additional National Security Vetting clearance (Security Check) before a start date can be offered. Further information regarding National Security Vetting clearance can be found here - National security vetting: clearance levels - GOV.UK Equality Statement Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation., * Design and deliver secure cloud architectures across IaaS, PaaS, and SaaS environments, embedding security controls aligned to organisational policy and industry best practice. * Lead the implementation of cyber security standards and controls across cloud platforms, influencing delivery teams and ensuring security is built in from the outset. * Provide senior cyber security consultancy, including cloud risk assessments, threat modelling, architecture reviews, audits, and contribution to cyber strategy. * Work closely with Architecture teams to shape secure target architectures and ensure security requirements are reflected in technical designs. * Lead and enhance cloud security operations, including but not limited to identity and access management, vulnerability management, logging, monitoring, and incident response. * Design and implement automated security controls and assurance, including policy as code, secure configuration baselines, and continuous compliance. * Translate security requirements into engineering level guidance, supporting developers and engineers to remediate issues and adopt secure coding and deployment practices. * Engage with internal and external stakeholders, providing security assurance, clear risk articulation, and support for change associated with security improvements. * Act as a technical mentor, championing cloud security best practice and supporting the development of engineers and security practitioners. * Design, review, and implement secure cloud infrastructure using Infrastructure as Code (IaC) tooling, embedding security controls, configuration standards, and policy as code into automated deployment pipelines (e.g. Terraform, CloudFormation), and providing assurance that environments are secure, consistent, and resilient. ## Related Videos - [Shifting Stress to Progress— Understanding DevOps to do DevOps Better](https://www.wearedevelopers.com/videos/268-shifting-stress-to-progress-understanding-devops-to-do-devops-better) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [A Brief History of Data Storage](https://www.wearedevelopers.com/videos/974-a-brief-history-of-data-storage) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)