> Markdown version of [/jobs/ext/348564-security-engineer-enterprise-markets](https://www.wearedevelopers.com/jobs/ext/348564-security-engineer-enterprise-markets). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - Enterprise Markets - **Company:** ! Gamma - **Location:** Newbury, UK - **Contract:** Permanent contract - **Skills:** User Authentication, Software as a Service, Cloud Computing, Cyber Security, Identity and Access Management, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Network Security, PCI Data Security Standards, Zero Trust Network Access, RSA (Cryptosystem), Security Information and Event Management, Software Vulnerability Management, Mitre Att&ck, Firewalls (Computer Science), Nessus, Microsoft Sentinel, Cisco, Qualys, Vulnerability Analysis - **Published:** June 19, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=165821e9a5899c58 ## About the Role Do you have experience in VPN?, * Strong experience in delivering vulnerability management services, ideally within a managed service or consultancy environment * Deep understanding of vulnerability lifecycle management (discovery / assessment / remediation / validation / reporting) * Hands-on experience with Tufin (SecureTrack / SecureChange) or similar tools such as Palo Alto Panorama or Cisco Defense Orchestrator * Proficiency with vulnerability scanning tools (Qualys, Nessus, Rapid7) * Solid knowledge of network security principles (firewalls, VPNs, segmentation, protocols) * Experience working with client stakeholders and managing competing priorities * Ability to translate technical vulnerabilities into business risk and remediation actions * Strong analytical, troubleshooting, and communication skills Nice to haves * Certifications such as CCNA / Security+ / CEH / CISSP (or working towards) * Experience in multi-client or managed security service provider (MSSP) environments * Familiarity with multi-vendor firewalls (Cisco, Palo Alto, Check Point) * Knowledge of compliance frameworks (ISO 27001, NIST, CIS, PCI-DSS) * Exposure to risk-based vulnerability management and threat intelligence integration * Understanding of ITIL service delivery and SLA-driven environments * Experience with SASE, Zero Trust, MDR/XDR platforms * Experience with RSA Authentication Manager or similar IAM solutions ## Description We are seeking a skilled and client-focused Security Engineer with strong expertise in Vulnerability Management and Network Security engineering. This role operates within a managed service provider environment, delivering security services to enterprise clients, with a primary focus on risk-based vulnerability management alongside network security, firewall optimisation, and access control. The successful candidate will be responsible for identifying, assessing, prioritising, and driving remediation of vulnerabilities across complex enterprise environments. In addition, they will contribute to strengthening overall cyber resilience by aligning vulnerability management with Managed Detection and Response (MDR) operations, supporting Secure Access Service Edge (SASE) frameworks, and advancing Zero Trust security models across network, identity, and access control layers. This is a hands-on engineering role requiring deep technical expertise across vulnerability management and network security, combined with strong stakeholder engagement. The role ensures security risks are proactively reduced, controls are optimised, and remediation is delivered in line with contractual SLAs and cyber security best practices. What will you be doing day-to-day?, Vulnerability Management Services * Deliver end-to-end vulnerability management services to clients, including discovery, assessment, prioritisation, reporting, and remediation tracking * Operate and maintain vulnerability scanning tools (e.g., Qualys, Nessus, Rapid7) across multiple client environments * Perform regular vulnerability scans, validation, and re-testing to ensure remediation effectiveness * Analyse vulnerability data, eliminate false positives, and provide actionable remediation guidance tailored to client environments * Prioritise vulnerabilities using risk-based methodologies (CVSS, exploitability, business impact, threat intelligence) * Track remediation activities and ensure closure within agreed SLAs and service metrics * Produce client-facing reports, dashboards, and service reviews, highlighting risk posture, trends, and key improvement areas * Act as a trusted advisor to clients, providing best practice recommendations on vulnerability and risk reduction strategies Security Engineering & Detection * Support deployment and optimisation of Microsoft Sentinel and SIEM/XDR platforms * Contribute to detection engineering (use case development, rule tuning, alert optimisation) * Onboard and integrate telemetry across network, endpoint, cloud, and identity sources * Support threat detection across SIEM, NDR, and identity platforms * Collaborate with SOC teams to improve detection coverage and reduce false positives * Align vulnerability insights with MDR workflows and threat detection use cases Network Security & Remediation * Identify, analyse, and manage network and system vulnerabilities across enterprise environments * Collaborate with infrastructure, cloud, and application teams to drive remediation activities to completion * Troubleshoot and resolve network/security issues linked to vulnerabilities and access controls * Support secure network architecture and ensure adherence to security and compliance standards * Support SASE architectures (e.g. Prisma, Cisco Secure) and secure connectivity models * Contribute to Zero Trust implementation, including least privilege and identity controls * Strengthen security posture across hybrid environments (network, cloud, SaaS, identity) Pre-Sales & Client Engagement * Support pre-sales activities, including solution design and vulnerability management offerings * Provide SME input into RFPs, bids, and technical workshops * Assist with onboarding clients and transitioning services into BAU * Build strong client relationships and act as a trusted technical advisor * Support service adoption and continuous improvement initiatives Governance, Reporting & Documentation * Maintain accurate records of vulnerabilities, remediation plans, and audit evidence * Support client audits, compliance requirements, and security assessments * Contribute to service improvement initiatives, automation, and process optimisation * Ensure adherence to ITIL-based service management practices where applicable Breach attack simulation (BAS) * Design, implement, and maintain Breach & Attack Simulation (BAS) scenarios to continuously validate the effectiveness of security controls across the enterprise. * Configure and operate BAS platforms to simulate real-world threat actor techniques (MITRE ATT&CK aligned) and identify control gaps. * Analyse BAS results to prioritise vulnerabilities, misconfigurations, and detection gaps, feeding findings into the vulnerability management lifecycle. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents)