Senior Security Engineer
Posted 2 days ago by Marlin Selection Ltd
Our client is a fast growing Commodities Focused Financial Services Firm based in London with offices in the US and Asia. They are seeking to recruit a Senior Security Engineer to join their London team.
Reporting to the IT Security Officer, you will work alongside the IT Security Engineer as part of a 3-person IT Security team. As the Senior Security Engineer, you will implement and maintain robust security systems and protocols across the IT infrastructure. You will conduct risk assessments and vulnerability scans, mitigate vulnerabilities identified in penetration testing, and implement preventative measures to protect against cyber threats. You will monitor the security infrastructure and detect and respond to potential threats. You will help mentor and develop the IT security engineer and collaborate with the IT team to ensure compliance with security standards and best practices; you will essentially be a key technical leader in safeguarding sensitive data and systems.
Key Responsibilities/Duties- Manage WAF and DDoS systems
- Manage the Web Security Gateway
- Manage the Email Security Gateway
- Manage the SIEM, SOAR, Identity Protection and EDR, and respond to alerts and threats
- Carry out vulnerability scans, identify risks, and remediation
- Manage the perimeter and VPN firewalls
- Manage MFA and SSO
- Manage MDM/MAM and Conditional Access
- Manage security certificates and keys
- Manage IDS and IPS
- Manage PAM systems
- Deliver Cyber Security Awareness Training
- Remediate vulnerabilities and weaknesses identified during penetration testing
- Ad-hoc IT security projects
The successful candidate will have a good working knowledge and experience in managing the majority of the following technology stack:
- CrowdStrike EDR
- Mimecast Mail Security Gateway
- Duo
- Okta
- Rapid7 IVM, Tenable IO or Nessus
- Rapid7 IDR or CrowdStrike Next Gen SIEM
- Palo Alto Firewalls and Panorama
- InTune and Conditional Access
Experience using the following technology stack would be advantageous; understanding the principles is required.
- Imperva WAF and DDoS
- KnowBe4
- Digicert Certificates and Microsoft Certificate Services
- Ivanti or Automox patching
- AppCheck or Tenable WAS
- Desired Education: CISM, MS SC100, 200 and 900, OSCP or other penetration testing qualifications
- Industry: Financial services, SOC, Pentesting is desirable
- Personal Skills:
- Excellent inter-personal, written and verbal communication skills
- The ability to handle multiple priorities, tasks and projects simultaneously
- Clear and precise verbal and written communication
- Ability to deliver presentations to staff
- Cross functional influence, engagement and collaboration skills
- The position is usually based in London Head Office
- Hours: The team works on a shift pattern to ensure cover from 07:30-17:30 (07:30-16:30 two days of remote work, 08:30-17:30 three days in the office)
- There will be periods of the weekend and out-of-hours work
If you can adhere to the above please apply.
Can't find the job you're looking for, send us your info and we will review your options?