> Markdown version of [/jobs/ext/348337-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/348337-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Cloudsman IT Solutions Limited - **Location:** Romford, UK - **Salary:** £48,500.0 - £54,500.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Amazon Web Services, Microsoft Azure, Backup Devices, Remote Backup Services, Bash Shell, Software as a Service, Cloud Computing Security, Static Program Analysis, Cyber Security, Continuous Integration, Data Recovery, Web Development, Infrastructure as a Service (IaaS), Identity and Access Management, Mobile Application Software, Python (Programming Language), Microsoft Office, Platform as a Service (PAAS), Systems Development Life Cycle, Security Information and Event Management, Software Engineering, SonarQube, Scripting, Delivery Pipeline, Software Security, Mitre Att&ck, Information Technology, Epic ECSA, Jenkins, Static Application Security Testing - **Published:** June 19, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=36c4ae9a737b5fa0 ## About the Role Do you have experience in SIEM?, * Demonstrable experience designing, implementing, testing and maintaining cyber security systems. * Hands-on experience building and operating CI/CD and application security tooling, ideally Jenkins, SonarQube, and Dependency-Track or equivalents. * Experience building and operating a SIEM (e.g. Wazuh, Elastic) and endpoint visibility tooling such as osquery. * Strong knowledge of security testing categories, SAST and SCA and integrating them into delivery pipelines. * Ability to examine systems for threats, develop and document test plans, and root-cause security issues. * Experience leading or supporting security incident and breach response, including evidence gathering and analysis. * Understanding of threat frameworks (e.g. MITRE ATT&CK, Cyber Kill Chain) and how they inform detection and response. * Knowledge of cloud security (IaaS, PaaS, SaaS), application security, and secure design of web and mobile applications. * Working knowledge of Microsoft 365 / Office 365, cloud backup architectures, encryption, and identity and access management. * Excellent problem-solving and communication skills, comfortable advising technical teams and clients. Desirable * Relevant certifications such as CEH (Certified Ethical Hacker) and ECSA (EC-Council Certified Security Analyst); others welcome (e.g. CISSP, CSSLP, OSCP, AWS/Azure security). * Experience in a fast-moving, Agile, cloud-first environment. * Familiarity with secure configuration of backup and CCTV/physical security platforms. * Scripting/automation skills (e.g. Python, Bash) for security tooling. ## Description As Cyber Security Engineer you will design, implement, test and maintain Cloudsman's cyber security systems across our development pipelines, hosted client environments, backup infrastructure, and internal systems. You will build and operate our application security tooling, a Jenkins-based CI/CD security platform, a Dependency-Track instance for software composition analysis, and a SonarQube platform for static code analysis, alongside a Wazuh SIEM, examine systems for threats, develop and document security test plans, and lead the response to security breaches., * Design, implement, test and maintain cyber security systems and tooling across Cloudsman's web development, application development, email, backup, and hosting environments. * Examine IT systems for potential threats to their security and integrity, and draw up response plans for situations where security is compromised. * Design, deploy and administer a Jenkins-based CI/CD security platform, integrating automated security testing into build pipelines so that tests run on each commit and builds fail against defined compliance thresholds. * Build and maintain a SonarQube platform to perform static application security testing (SAST) and code analysis, defining quality gates that govern release. * Build and maintain a Dependency-Track platform to provide continuous software composition analysis (SCA) and software bill of materials (SBOM) visibility across development projects. * Build and operate a Wazuh SIEM platform to collect and correlate logs across hosting, backup and development environments, investigate security incidents, analyse evidence, and produce findings for management and clients. * Deploy osquery across endpoints and servers to provide host-level visibility, feeding telemetry into the SIEM for detection and threat hunting. * Develop test plans for security systems, and undertake and document the testing of security systems for weaknesses and errors, identify the source of problems, and propose solutions. * Develop quality standards, validation techniques, and secure configuration baselines for development, hosting, Microsoft 365 / Office 365 backup, data recovery, and CCTV systems. * Identify, analyse and report on outstanding end-of-life, vulnerable, and high-risk components and code-analysis findings, and ensure remediation requests are tracked and resolved. * Deal with and report on breaches in security, leading investigation, containment, and post-incident review. * Make recommendations concerning software and system quality, and advise development and infrastructure teams on secure-by-design practices across the SDLC. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Automated Code Quality Checks with Custom SonarQube Rules](https://www.wearedevelopers.com/videos/428-automated-code-quality-checks-with-custom-sonarqube-rules) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [The Road to MLOps: How Verivox Transitioned to AWS](https://www.wearedevelopers.com/videos/1050-the-road-to-mlops-how-verivox-transitioned-to-aws) - [Automated MS SQL Server database deployments with dacpacs and Azure DevOps](https://www.wearedevelopers.com/videos/334-automated-ms-sql-server-database-deployments-with-dacpacs-and-azure-devops) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)