Job Search and Career Advice Platform

Enable job alerts via email!

Security Test Engineer

McNally Recruitment Ltd

Cumbernauld

Hybrid

GBP 45,000 - 65,000

Full time

26 days ago

Generate a tailored resume in minutes

Land an interview and earn more. Learn more

Job summary

A leading recruitment agency is seeking a Security Test Engineer to ensure the security robustness of software and firmware components. The role involves conducting threat modeling, security testing, and vulnerability assessments. Candidates should have a minimum of 5 years' experience and be familiar with various security tools. This hybrid position requires 4 days in the Scottish office and candidates must be located in Scotland.

Qualifications

  • Minimum 5 years of experience in software and/or firmware testing.
  • Proficient in security testing tools and scripting languages.
  • Strong understanding of common vulnerabilities and industry standards.

Responsibilities

  • Perform security requirements analysis and threat modeling.
  • Plan, execute, and report on security testing activities.
  • Ensure compliance with internal processes and applicable standards.

Skills

Cybersecurity knowledge
Threat modeling
Vulnerability assessments
Scripting languages (Python, Bash)
Security testing tools (Burp Suite, OWASP ZAP)

Education

Engineering degree in Software, Computer Science, Cybersecurity

Tools

Burp Suite
Nessus
Wireshark
Metasploit
Job description

The Security Test Engineer will be responsible for ensuring the security robustness of software and firmware components within our product portfolio. This role involves conducting threat modeling, security testing, and vulnerability assessments, while ensuring compliance with internal processes and industry standards. The ideal candidate will be passionate about cybersecurity, detail-oriented, and experienced in testing within industrial environments.

PLEASENOTEtheclientwillonlyacceptcandidateswhoareauthorisedtoworkintheUK,withouttherequirementforsponsorshiporANYtypeofvisa(e.g.dependant/spousal,post-studyetc.).

Inaddition,thisrolehybridbasedwith4daysintheScottishoffice,thereforeyoushouldcurrentlybelocatedinScotland.

PRINCIPLE JOB RESPONSIBILITIES
  • Perform security requirements analysis and threat modeling.
  • Conduct risk analysis and define test strategies aligned with security objectives.
  • Plan, execute, and report on security testing activities, including:
    • Tool and technique selection
    • Security requirements testing
    • Threat mitigation testing
    • Vulnerability testing
    • Abuse case testing
    • Attack surface analysis
    • Regression testing
    • Test automation
  • Analyze, report, and track security defects.
  • Ensure compliance with internal processes and applicable standards (e.g. IEC 62443, ISO 27001).
  • Support internal and external audits as required.
  • Drive continuous improvement by staying updated on emerging threats, tools, and best practices.
  • Occasional travel may be required, such as training or customer support.
REQUIRED QUALIFICATIONS AND EXPERIENCE
  • Minimum 5 years of experience in software and/or firmware testing
  • Engineering degree in Software, Computer Science, Cybersecurity or equivalent demonstrated knowledge.
  • Proficiency with tools such as Burp Suite, OWASP ZAP, Nessus, Metasploit, Wireshark, Nmap, Fortify, Checkmarx.
  • Knowledge of scripting languages such as Python, JavaScript, Bash, or PowerShell.
  • Understanding of encryption algorithms, key management, and secure protocols (TLS, SSH, etc.).
  • Strong understanding of common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).
  • Familiarity with Linux, Windows, and network protocols (TCP/IP, DNS, HTTP/S).
  • Understanding of industrial protocols (e.g., Serial, Modbus, HART).
  • Knowledge of industry standards: IEC 62443, ISO 27001, NIST, OWASP.
  • Experience implementing DevSecOps best practices; Azure DevOps experience is a plus.
  • Self-directed and motivated in a team oriented environment.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.