Cyber Security Engineer

Hellios Information

Oxford

On-site

GBP 70,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A supplier information and risk management company is seeking a Cyber Security Engineer to establish and maintain cybersecurity strategies aligned with EU regulatory requirements. The role requires over 10 years of experience in information security, with a strong emphasis on governance, risk management, and incident response. The candidate must have educational credentials in a relevant field and certifications like CISSP or CISM. This position offers opportunities to significantly impact the cybersecurity posture of a rapidly growing organization.

Qualifications

  • 10+ years in information security, with at least 5 years in a cybersecurity engineering role.
  • Experience operating in regulated environments (e.g., financial services, healthcare, telecoms).
  • Proven experience leading incident response at enterprise scale.

Responsibilities

  • Develop, implement, and maintain information security strategy.
  • Ensure compliance with GDPR and relevant frameworks.
  • Oversee security operations and incident response.

Skills

Cybersecurity Strategy
Risk Management
Compliance
Incident Response
Cloud Security

Education

Bachelor’s in Information Security, Computer Science, Engineering, or related field
CISSP
CISM
CRISC
CISA
ISO 27001 Lead Implementer/Auditor

Tools

ISO 27001
NIST CSF
AWS
Azure
GCP

Job description

Location

Kemp House, Chawley Park, Cumnor, Oxford

Job Title

Cyber Security Engineer

Reporting To

Chief Information Security Officer

Job Summary

To support and evolve our web‑based Supplier Information & Risk management systems and business offerings. The Cyber Security Engineer is responsible for establishing and maintaining the enterprise vision, strategy, and programme to ensure information assets, technologies, and data are adequately protected. This role will lead the organisation’s cybersecurity strategy in alignment with Irish and EU regulatory requirements including GDPR, NIS2 Directive, DORA (where applicable), and Central Bank of Ireland guidance (if regulated). The Cyber Security Engineer will work closely with executive leadership and the Board to manage cyber risk and ensure resilience across the organisation.

Key Responsibilities
  • Cybersecurity Strategy & Governance
    • Develop, implement, and maintain the enterprise‑wide information security strategy.
    • Align security initiatives with business objectives and risk appetite.
    • Establish and maintain security governance frameworks (e.g., ISO 27001, NIST CSF, Cyber Essentials).
    • Report regularly to the Executive Team and Board on cybersecurity posture and risk.
  • Risk Management & Compliance
    • Lead enterprise cyber risk assessments and mitigation programmes.
    • Ensure compliance with:
      • GDPR and Data Protection Commission guidance
      • NIS2 Directive (where applicable)
      • DORA (for financial services organisations)
    • Oversee third‑party and supply‑chain security risk management.
    • Lead audit engagements and regulatory inspections related to cybersecurity.
  • Security Operations & Incident Response
    • Oversee security operations including SOC, threat detection, and vulnerability management.
    • Develop and maintain incident response and crisis management plans.
    • Lead response to major security incidents and coordinate with regulators and law enforcement where necessary.
    • Ensure business continuity and disaster recovery capabilities are robust and tested.
  • Architecture & Engineering Oversight
    • Provide security architecture oversight for cloud, on‑premises, and hybrid environments.
    • Ensure secure software development practices (DevSecOps).
    • Oversee identity and access management (IAM) and zero‑trust initiatives.
  • Data Protection & Privacy
    • Work closely with the Data Protection Officer (DPO) to ensure technical and organisational measures are appropriate.
    • Ensure strong data classification, encryption, and retention controls.
  • Leadership & Culture
    • Develop cybersecurity awareness programmes across the organisation.
    • Foster a strong security‑first culture.
Required Experience & Qualifications
  • Bachelor’s in Information Security, Computer Science, Engineering, or related field.
  • Relevant professional certifications such as:
    • CISSP
    • CISM
    • CRISC
    • CISA
    • ISO 27001 Lead Implementer/Auditor
Experience
  • 10+ years in information security, with at least 5 years in a cybersecurity engineering role.
  • Experience operating in regulated environments (e.g., financial services, healthcare, telecoms).
  • Strong knowledge of cybersecurity regulatory frameworks.
  • Proven experience leading incident response at enterprise scale.
  • Experience reporting to Board‑level stakeholders.
Technical Expertise
  • Security frameworks: ISO 27001, NIST CSF, COBIT
  • Cloud security (AWS, Azure, GCP)
  • Identity & Access Management (IAM)
  • SIEM, SOAR, EDR/XDR platforms
  • Threat intelligence and vulnerability management
  • Data protection technologies
  • Secure SDLC and DevSecOps practices
Competencies & Attributes
  • Strategic thinker with strong commercial awareness
  • Excellent communication and stakeholder management skills
  • Strong leadership and team development capability
  • High integrity and ethical standards
  • Crisis management expertise
  • Ability to influence at Board and Executive level
The Company

Hellios is a leading supplier information and risk management company operating in the financial services and defence industry. Established with the primary objective to benefit major blue‑chip companies and their suppliers, Hellios provides a single streamlined approach by sharing data across an industry community in areas including modern slavery, cyber security and GDPR. Since its inception as a startup in 2012, Hellios has experienced rapid growth, expanding to over 145 employees and establishing offices across the UK, The Netherlands, Spain, and Ireland. The Company is continuing to grow quickly, and a key part of this role is to prepare the Company for further growth. At Hellios, we are guided by an ethos centred on delivering unparalleled service quality and innovative technology. Our commitment rests upon nurturing enduring, sustainable relationships with both our buyer and supplier clientele.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

Hellios Information Limited • Cumnor

On-site
GBP 70,000 - 100,000
Customer Success Manager JOSCAR
Customer Success Manager JOSCAR

Hellios • Oxford

On-site
GBP 40,000 - 55,000
Performance related bonus
25 days holiday
Company pension scheme
+1
Cybersecurity Engineer
Cybersecurity Engineer

Healix International • Esher

On-site
GBP 65,000 - 95,000
Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Cybersecurity Engineer - Belfast
Cybersecurity Engineer - Belfast

Morson Human Resources Limited • Belfast City District

On-site
GBP 55,000 - 75,000
Hybrid Belfast
Permanent position
Competitive salary
+2
Cybersecurity Engineer
Cybersecurity Engineer

SeeMeHired.com • Esher

On-site
GBP 90,000 - 130,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

MCS Group | Your Specialist Recruitment Consultancy • Belfast

Hybrid
GBP 70,000 - 90,000
Healthcare
Pension
Additional company benefits
Head of Infosec - Fintech - Hybrid
Head of Infosec - Fintech - Hybrid

Wealth Dynamix • Greater London

Hybrid
GBP 120,000 - 180,000
Senior Cyber Security Engineer: Strategy & Incident Response
Senior Cyber Security Engineer: Strategy & Incident Response

Hellios Information Limited • Cumnor

On-site
GBP 70,000 - 100,000
Cyber & Information Security Lead
Cyber & Information Security Lead

Computer Network Defence Ltd (CND) • Bath

Hybrid
GBP 90,000 - 130,000