Cyber Security Engineer

Cloudsman IT Solutions Limited
Romford, UK
about 2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
£48,500.0 - £54,500.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Agile Methodology Amazon Web Services Microsoft Azure Backup Devices Remote Backup Services Bash Shell Software as a Service Cloud Computing Security Static Program Analysis Cyber Security Continuous Integration
+20 more
Data Recovery Web Development Infrastructure as a Service (IaaS) Identity and Access Management Mobile Application Software Python (Programming Language) Microsoft Office Platform as a Service (PAAS) Systems Development Life Cycle Security Information and Event Management Software Engineering SonarQube Scripting Delivery Pipeline Software Security Mitre Att&ck Information Technology Epic ECSA Jenkins Static Application Security Testing

Job description

As Cyber Security Engineer you will design, implement, test and maintain Cloudsman’s cyber security systems across our development pipelines, hosted client environments, backup infrastructure, and internal systems. You will build and operate our application security tooling, a Jenkins-based CI/CD security platform, a Dependency-Track instance for software composition analysis, and a SonarQube platform for static code analysis, alongside a Wazuh SIEM, examine systems for threats, develop and document security test plans, and lead the response to security breaches., * Design, implement, test and maintain cyber security systems and tooling across Cloudsman’s web development, application development, email, backup, and hosting environments.

  • Examine IT systems for potential threats to their security and integrity, and draw up response plans for situations where security is compromised.
  • Design, deploy and administer a Jenkins-based CI/CD security platform, integrating automated security testing into build pipelines so that tests run on each commit and builds fail against defined compliance thresholds.
  • Build and maintain a SonarQube platform to perform static application security testing (SAST) and code analysis, defining quality gates that govern release.
  • Build and maintain a Dependency-Track platform to provide continuous software composition analysis (SCA) and software bill of materials (SBOM) visibility across development projects.
  • Build and operate a Wazuh SIEM platform to collect and correlate logs across hosting, backup and development environments, investigate security incidents, analyse evidence, and produce findings for management and clients.
  • Deploy osquery across endpoints and servers to provide host-level visibility, feeding telemetry into the SIEM for detection and threat hunting.
  • Develop test plans for security systems, and undertake and document the testing of security systems for weaknesses and errors, identify the source of problems, and propose solutions.
  • Develop quality standards, validation techniques, and secure configuration baselines for development, hosting, Microsoft 365 / Office 365 backup, data recovery, and CCTV systems.
  • Identify, analyse and report on outstanding end-of-life, vulnerable, and high-risk components and code-analysis findings, and ensure remediation requests are tracked and resolved.
  • Deal with and report on breaches in security, leading investigation, containment, and post-incident review.
  • Make recommendations concerning software and system quality, and advise development and infrastructure teams on secure-by-design practices across the SDLC.

Requirements

Do you have experience in SIEM?, * Demonstrable experience designing, implementing, testing and maintaining cyber security systems.

  • Hands-on experience building and operating CI/CD and application security tooling, ideally Jenkins, SonarQube, and Dependency-Track or equivalents.
  • Experience building and operating a SIEM (e.g. Wazuh, Elastic) and endpoint visibility tooling such as osquery.
  • Strong knowledge of security testing categories, SAST and SCA and integrating them into delivery pipelines.
  • Ability to examine systems for threats, develop and document test plans, and root-cause security issues.
  • Experience leading or supporting security incident and breach response, including evidence gathering and analysis.
  • Understanding of threat frameworks (e.g. MITRE ATT&CK, Cyber Kill Chain) and how they inform detection and response.
  • Knowledge of cloud security (IaaS, PaaS, SaaS), application security, and secure design of web and mobile applications.
  • Working knowledge of Microsoft 365 / Office 365, cloud backup architectures, encryption, and identity and access management.
  • Excellent problem-solving and communication skills, comfortable advising technical teams and clients.

Desirable

  • Relevant certifications such as CEH (Certified Ethical Hacker) and ECSA (EC-Council Certified Security Analyst); others welcome (e.g. CISSP, CSSLP, OSCP, AWS/Azure security).
  • Experience in a fast-moving, Agile, cloud-first environment.
  • Familiarity with secure configuration of backup and CCTV/physical security platforms.
  • Scripting/automation skills (e.g. Python, Bash) for security tooling.

Benefits & conditions

Pulled from the full job description

  • UK visa sponsorship
  • On-site parking

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:02 min

Applying an ETL methodology to infrastructure configuration management

Axel Barbier Ā· WWC 2023

3:23 min

Building and installing the compiled custom rule extension

Daniel Strmečki +1 Ā· WWC 2022

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders Ā· LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

57 sec

Extracting API schemas automatically during continuous integration builds

Axel Barbier Ā· WWC 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin Ā· WWC 2022

Videos

See all

Related articles

See all