Information Security Engineer

Clyde & Co

Glasgow

Hybrid

GBP 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Life assurance from day one
Wellbeing support
Lifestyle discounts

Job summary

Clyde & Co in Glasgow is seeking an experienced Information Security professional to act as a trusted advisor across projects and internal changes, focusing on secure design and cloud environments (Azure / MS 365). You will collaborate with IT, Architecture and Cyber teams, lead security assurance for cloud services, and drive risk assessments, compliance and remediation with external testing as required.

This role combines hands‑on delivery with strategic policy development and mentoring,

Qualifications

  • Proven experience in Information Security with a technical focus.
  • Experience with risk assessments and design reviews across diverse environments.
  • Knowledge of SIEM (CrowdStrike / MS Sentinel), EDR, Vulnerability Management and firewalls.
  • Proven experience with Azure / MS365 E5 security suite (Defender, CA policies, CASB).
  • Experience with AI technologies and agentic AI risk considerations desirable.
  • Knowledge of MS Purview capabilities (Information Protection, DLP, Insider Risk Management) desirable.
  • Solid IT fundamentals across Networking, Server, Storage, Virtualisation, Desktop.
  • Ability to construct queries in KQL / CQL for investigations and reporting.
  • Experience with SAST/DAST, CI/CD, cloud orchestration and automation tools desirable.
  • As SME, mentor other InfoSec and IT teams as required.

Responsibilities

  • Provide internal security consultancy and support across projects and internal changes.
  • Attend and contribute to Technical Design Authority reviews for security assurance.
  • Work with IT teams to assess changes and ensure security controls are integrated.
  • Collaborate with Solution Architects to ensure secure designs and audit implementations.
  • Lead cloud security for Azure / MS365 and advise on ongoing health and improvements.
  • Ensure designs and configurations comply with Cyber Essentials Plus and CIS standards.
  • Develop hardening standards for onboarding new technologies.
  • Maintain hands‑on involvement in evaluation, design and risk assessment.
  • Coordinate external PEN/Web App testing and remediation activities with project teams.
  • Support Cyber Defence with data sources, event types, alerts and use-case development.
  • Stay current on emerging technologies and vulnerabilities relevant to the firm.
  • Assist Cyber Solutions Lead in developing the Cyber Solution Strategy.
  • Embed Security Architecture considerations with Enterprise Architect teams.
  • Mature Security Architecture Policies and Standards documentation.

Skills

Information Security
Cloud Security
Azure MS365
Risk Assessments
Security Architecture
Threat Modelling
SIEM/EDR Tools
KQL/CQL
Python scripting
Communication

Tools

CrowdStrike
MS Defender
Rapid7
Firewalls
CI/CD Pipelines

Job description

Type: Full Time
Duration: Permanent
Location: Glasgow
Working Pattern: +2 days working from the office, 3 days remote
Department: Information Security

The Role

This role acts as a trusted Information Security advisor, providing consultancy and hands‑on support across project‑based initiatives and internal change. You will work closely with IT, Architecture, and Cyber teams to ensure secure design, implementation, and continuous assurance of technologies across the firm, with a strong focus on cloud environments (Azure / M365).

Key Responsibilities
  • As a trusted InfoSec advisor provide internal consultancy and support to your peers and the wider team working on project‑based initiatives and internal changes.
  • Attend and participate in the Technical Design Authority to provide expert security review and ensure assurance of new designs and initiatives.
  • Work closely with all IT teams (Cloud, Network, Infrastructure, Data etc.) to ensure continuous risk assessment is undertaken for changes and ensure additions to the environment are assessed against industry best practice.
  • Work closely with Solution Architects to ensure high and low‑level designs consider security control requirements against industry standards. Where required audit final implementations against the approved designs.
  • Lead the security assurance capability for the cloud services in use at the firm with a focus on Azure / MS 365 initially. Advise on the continuous health of the environments and propose security control improvements as required.
  • Ensure all designs and platform configurations are in compliance with Cyber Essentials Plus, CIS standards and technical requirements agreed with clients.
  • Work with the teams to update or create hardening standards for existing or new technologies as they are onboarded.
  • This role requires an element of hands‑on approach for evaluation, design and risk assessment to ensure security outcomes can be fully defined and progressed effectivity.
  • As external security testing is required (PEN / Web App testing etc) liaise with testing providers and project teams to ensure the scope is well defined and testing is successfully completed. Work with the project teams to ensure remediation actions are completed and retesting takes place.
  • Support the Cyber Defence team with ensuing all new technologies are onboarded successfully by identifying the correct data sources, event type and alerts to be captured. Work with the Cyber Defence team and the managed security service provider to build suitable use cases.
  • Stay current and up to date on new emerging technologies and associated vulnerabilities and risk.
  • Assist the Cyber Solutions Lead with developing the Cyber Solution Strategy for the firm. Ensure the firm continues to have robust and effective security controls in place whilst maximising utilisation of existing technologies and synergies.
  • Work with the Enterprise Architect team to ensure Security Architecture considerations are embedded into existing design and assurance processes.
  • Work with the Cyber Solutions Lead to mature existing Security Architecture Polices and Standards documentation and ensure alignment to current best practices.
Essential Skills & Experience
  • Proven experience of working in an Information Security / Cyber Security role with a technical focus. Experience within the legal or professional services industry is ideal, but not essential.
  • Proven experience of undertaking risk assessments and technical design reviews with the ability to absorb information quickly across a broad and diverse environment whilst identifying key areas for further scrutiny.
  • Working knowledge of SIEM (CrowdStrike / MS Sentinel), Endpoint Detection & Response (CrowdStrike / MS Defender), Vulnerability Management (Rapid7), Firewalls, and industry standard security tools.
  • Proven experience working with the Azure / MS365 E5 security suite (Defender, Conditional Access Policies, CASB etc.). Demonstrable knowledge of the security controls available and how to pragmatically implement them to maximize the firm’s security posture.
  • Experience working with AI technologies, implementing or risk assessing agentic AI agents and MCP Server / Client implementations. Open AI / Co Pilot focused skills desirable.
  • Demonstrable knowledge of implementing MS Purview and its various capabilities such as Information Protection, DLP, Insider Risk Management is desirable but not essential.
  • Good overall knowledge of IT technologies and processes i.e., Networking, Server (Windows / Linux), Storage, Virtualisation, Desktop etc
  • Good working knowledge of the Kusto Query Language (KQL) or CrowdStrike Query Language (CQL) and ability to construct queries for investigations and reporting would be advantageous.
  • Experience working with SAST / DAST technologies, CI/CD pipelines, cloud orchestration and automation tools, PowerShell or Python scripting would be desirable but not essential.
  • As a Subject Matter Expert be able to support, advise, guide and mentor other members of the InfoSec and IT teams as required.
  • Strong organisational skills and the ability to handle multiple conflicting priorities.
  • Able to work to very tight deadlines under pressure and to assimilate information quickly.
  • Strong interpersonal skills including confidence, positivity, diplomacy, and the ability to gain credibility quickly.
  • Excellent verbal and written communication skills, with the ability to explain technical terms in a way that non‑technical persons would understand.
  • Demonstrates attention to detail with a high level of accuracy.
  • Positive and tenacious with the ability to pro‑actively drive initiatives forward and motivate resources within and outside their team to perform.
What Sets This Role Apart
  • Opportunity to shape and mature security architecture in a global firm
  • Exposure to modern cloud, AI, and security technologies
  • A highly collaborative environment with influence across IT and business teams
What’s In It For You
  • Modern, flexible working – A minimum of 2 days each week required from the office, 3 days from home.
  • Join an award‑winning global firm with strong career progression opportunities, structured development programmes, and internal mobility.
  • Recognised for inclusivity, pro bono work, and global DEI initiatives.
  • Benefits include life assurance from day one, wellbeing support, lifestyle discounts, and more.
Our Commitment

Clyde & Co is proud to be an equal opportunities employer. Our values encourage us to support fairness, celebrate diversity and prohibit all forms of discrimination in the workplace to allow everyone to excel at work. Therefore, we welcome and encourage all applications from suitably qualified individuals, regardless of background or identity.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Specialist
Senior Information Security Specialist

Clyde & Co • Glasgow

Hybrid
GBP 90,000 - 120,000
Principal Information Security Engineer
Principal Information Security Engineer

Manchester Digital • Manchester

On-site
GBP 70,000 - 95,000
26 days holiday
Pension 7% matched
Discretionary bonus
+6
Cyber Security Analyst/Lead
Cyber Security Analyst/Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Information Security Architect
Information Security Architect

i3 • Greater London

Hybrid
GBP 70,000 - 90,000
Opportunity to work on cutting-edge technologies
Security Operations Specialist
Security Operations Specialist

Cyber UK • Glasgow

Hybrid
GBP 45,000 - 65,000
Competitive salary
Private medical insurance
Life assurance
+5
Cyber Security Analyst
Cyber Security Analyst

SmartestEnergy • Ipswich

On-site
GBP 50,000 - 75,000
Flexible Working
Diversity and Inclusion Commitment
IT Cyber Security Specialist
IT Cyber Security Specialist

Slaughter and May • Greater London

On-site
GBP 90,000 - 120,000
Security Architect - Systems Integrator
Security Architect - Systems Integrator

Hamilton Barnes Associates Limited • Bristol

Remote
GBP 40,000 - 80,000
Structured career development
Competitive salary
Bonus scheme
+4
Cyber Security Engineer
Cyber Security Engineer

REX Cyber Security • Leeds

On-site
GBP 70,000 - 84,000
Up to 20% bonus
Comprehensive benefits package
Information Security Engineer
Information Security Engineer

Digital Gurus • Burton upon Trent

On-site
GBP 40,000 - 60,000
33 days' holiday
On-site canteen
Golf course access