Senior Cyber Security Engineer

Social Security Scotland

Glasgow

Hybrid

GBP 70,000 - 90,000

Full time

11 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

GDD pay supplement £4,000 annual

Job summary

Social Security Scotland is seeking a Senior Cyber Security Engineer on a fixed-term basis (47 months) to secure cloud platforms delivering public services. You will translate policy and risk into practical cloud security solutions, working with Architecture, Cloud Engineering, DevOps and Product teams in a cloud-first, hybrid environment spanning Glasgow or Dundee.

Your role includes designing secure cloud architectures, embedding security from inception, and leading security operations with

Qualifications

  • Experience implementing cloud native security controls (IAM, encryption, logging, monitoring).
  • Experience embedding security across the full delivery lifecycle.
  • Experience with automated security controls and policy as code using IaC tooling.

Responsibilities

  • Design and deliver secure cloud architectures across IaaS, PaaS, and SaaS.
  • Lead the implementation of cyber security standards across cloud platforms.
  • Provide senior cyber security consultancy including risk assessments and audits.
  • Collaborate with Architecture teams to shape secure target architectures.
  • Lead and enhance cloud security operations: IAM, vulnerability management, logging, monitoring, incident response.
  • Design and implement automated security controls and policy as code.

Skills

Cloud security
IAM
Threat modelling
Security monitoring
IaC tooling
Vulnerability management
Incident response

Tools

Terraform
CloudFormation
Policy as code

Job description

This is a Fixed Term Appointment opportunity for 47 months with the possibility of permanency dependent on business requirements. Social Security Scotland is seeking a Senior Cyber Security Engineer to help secure the cloud platforms that deliver vital public services. This is a key role in a cloud first organisation, working to ensure solutions are secure by design, resilient, and compliant. The Senior Cyber Security Engineer leads the design, implementation, and assurance of cyber security controls across cloud platforms, applications, and infrastructure. You will translate security policy and risk into practical cloud security solutions, working closely with Architecture, Cloud Engineering, DevOps, and Product teams. Acting as a technical authority, you will provide hands‑on expertise, assurance, and risk‑based guidance, embedding security throughout the delivery lifecycle. The Cyber Security Engineer builds, develops, and configures tooling and processes to be secure. They build tooling to support pre‑commit, Continuous Integration, Continuous Deployment through to production. They have experience of operating systems, Networking, PKI and Cloud Security tools. They build Secure Configuration Management using Infrastructure as Code.

  • Identify, design and develop cyber security solutions across a wide variety of applications and infrastructure
  • Lead the implementation of cyber security policy and standards
  • Provide senior cyber security consultancy services (from risk assessments and audits to strategy development) across a variety of technology projects
  • Engage with the Technology Architecture team and support the design of technology solutions and architecture for a variety of projects and programmes
  • Engage with a broad range of internal and external stakeholders, providing cyber security assurance and managing the change process for the implementation of cyber security strategy, standards and solutions.
Responsibilities
  • Design and deliver secure cloud architectures across IaaS, PaaS, and SaaS environments, embedding security controls aligned to organisational policy and industry best practice.
  • Lead the implementation of cyber security standards and controls across cloud platforms, influencing delivery teams and ensuring security is built in from the outset.
  • Provide senior cyber security consultancy, including cloud risk assessments, threat modelling, architecture reviews, audits, and contribution to cyber strategy.
  • Work closely with Architecture teams to shape secure target architectures and ensure security requirements are reflected in technical designs.
  • Lead and enhance cloud security operations, including but not limited to identity and access management, vulnerability management, logging, monitoring, and incident response.
  • Design and implement automated security controls and assurance, including policy as code, secure configuration baselines, and continuous compliance.
  • Translate security requirements into engineering level guidance, supporting developers and engineers to remediate issues and adopt secure coding and deployment practices.
  • Engage with internal and external stakeholders, providing security assurance, clear risk articulation, and support for change associated with security improvements.
  • Act as a technical mentor, championing cloud security best practice and supporting the development of engineers and security practitioners.
  • Design, review, and implement secure cloud infrastructure using Infrastructure as Code (IaC) tooling, embedding security controls, configuration standards, and policy as code into automated deployment pipelines (e.g. Terraform, CloudFormation), and providing assurance that environments are secure, consistent, and resilient.
Success Profiles

We use an assessment framework called ‘Success Profiles’ which lists the elements we test and provides detailed descriptions of each. Find out more about the framework here.

For this post, the following Success Profile elements will be assessed:

Experience
  • Experience implementing cloud native security controls such as IAM, encryption, key management, logging, and monitoring.
  • Experience embedding security across the full delivery lifecycle, from early design through to live operations.
  • Experience creating or implementing automated security controls and assurance, e.g. policy as code, configuration compliance, or security monitoring rules utilising IaC Tooling.
Behaviours
  • Leadership (Level 3)

You can find out more about Success Profiles Behaviours here.

Technical / Professional Skills:

This role is aligned to Senior Cyber Security Engineer within the Government Digital and Data Profession.

Please review the following to understand the skill expectations: Cyber Security Engineer - Cyber security: operations - gov.scot

These skills will be tested during the Technical Assessment if you are successful at sift stage. They will not be assessed at application stage.

Expected Timeline (subject to change)

Sift – week commencing 19th October 2026.

Interview – week commencing 2nd November 2026.

Location – In Person in either Dundee or Glasgow

Reserve List

In the event that there are more successful candidates than posts available, a reserve list will be kept for up to 12 months.

About Us

Social Security Scotland is an Executive Agency of the Scottish Government. Our benefits help people from all walks of life in Scotland. We offer rewarding careers and employ people across Scotland in a wide range of professions and roles. We are committed to recruiting a diverse workforce that is representative of the clients we serve. Find more about us here.

GDD Pay Supplement

This post is part of the Government Digital and Data (GDD) profession and currently attracts a £4,000 annual GDD pay supplement, which is paid monthly. Pay supplements are reviewed regularly.

Working Pattern

Our standard hours are 35 hours per week and we offer a range of flexible working options, depending on the needs of the role. We embrace a hybrid working style where all colleagues will spend time in either our Glasgow or Dundee offices. There is an expectation of a minimum 2 days per week in your assigned location, which will be either Glasgow or Dundee. If you have specific questions about the role you are applying for, please contact us.

Security Checks

Successful candidates must complete the Baseline Personnel Security Standard (BPSS), before they can be appointed. BPSS is comprised of four main pre-employment checks – Identity, Right to work, Employment History and a Criminal Record check (unspent convictions).

Due to the nature of this post, the successful candidate is also required to clear additional National Security Vetting clearance (Security Check) before a start date can be offered. Further information regarding National Security Vetting clearance can be found here -National security vetting: clearance levels - GOV.UK

Equality Statement

Social Security Scotland are committed to equality and inclusion, and we aim to recruit a diverse workforce that reflects the population of our nation.

Social Security Scotland are a Disability Confident Employer. We will consider and implement any reasonable adjustments you may require throughout the recruitment process and during the course of your employment, should you be successful in securing a post. If you feel you may require assistance with any part of our recruitment process, please contact us at Recruitment@socialsecurity.gov.scot.

Find out more about our commitment to diversity and how we offer and support recruitment adjustments for anyone who needs them.

Right to Work in the UK

Social Security Scotland is an approved sponsor under the UK Visa and Immigration (UKVI) Skilled Worker route. Please note that UK immigration guidance, including skill and salary thresholds and eligible occupations, is reviewed regularly and subject to change. If you require visa sponsorship, you should check the latest criteria to confirm whether this role meets current requirements before applying. You can find further advice at Skilled Worker visa: Overview - GOV.UK

Further Information

Social Security Scotland’s recruitment processes are underpinned by the recruitment principles of the Civil Service Commissioner, which outline that selection for appointment be made on merit on the basis of fair and open competition - Recruitment - Civil Service Commission

If you feel at any time your application has not been treated in accordance with the values in the Civil Service Code and/or if you feel the recruitment has been conducted in such a way that conflicts with the Civil Service Commissioner’s Recruitment Principles, you can make a complaint, by contacting Social Security Scotland at recruitment@socialsecurity.gov.scot in the first instance. If you are not satisfied with the response you receive you can contact the Civil Service Commissioner.

The successful candidate will be expected to remain in post for a minimum of 3 years unless successful in gaining promotion to a higher Band or Grade.

Find out more about our organisation, what we offer staff members and how to apply on our Careers Website.

Read our Candidate Guide for further information on our recruitment and application processes.

If you experience any difficulties accessing our website or completing the online application form, please contact the Resourcing Team via recruitment@socialsecurity.gov.scot

Contact Name- Resourcing Team

Contact email – Recruitment@socialsecurity.gov.scot

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Information and Cyber Security Officer
Senior Information and Cyber Security Officer

Scottish Government • Glasgow

Hybrid
GBP 70,000 - 90,000
Hybrid working
Disability Confident Employer
GDD pay supplement
+1
Principal Cyber Security Analyst (IAM)
Principal Cyber Security Analyst (IAM)

Social Security Scotland • Glasgow

Hybrid
GBP 90,000 - 120,000
Hybrid working
Senior Technical Delivery Manager (Fixed Term Appointment)
Senior Technical Delivery Manager (Fixed Term Appointment)

Social Security Scotland • Glasgow

Hybrid
GBP 75,000 - 100,000
Principal Cyber Security Analyst (IAM)
Principal Cyber Security Analyst (IAM)

Scottish Government • Glasgow

Hybrid
GBP 65,000 - 90,000
Hybrid working (Glasgow/Dundee)
£4,000 annual GDD pay supplement
Technical Architect
Technical Architect

Social Security Scotland • Glasgow

Hybrid
GBP 80,000 - 100,000
Business Analyst
Business Analyst

Social Security Scotland • Glasgow

Hybrid
GBP 45,000 - 65,000
Hybrid working
Product Owner
Product Owner

Social Security Scotland • Glasgow

Hybrid
GBP 65,000 - 90,000
Hybrid working
Employee benefits
Business Analyst
Business Analyst

Scottish Government • Glasgow

Hybrid
GBP 45,000 - 65,000
Case Manager
Case Manager

Social Security Scotland • Glasgow

Hybrid
GBP 30,000 - 38,000
Hybrid work pattern
Client Manager - Glasgow
Client Manager - Glasgow

Social Security Scotland • Glasgow

Hybrid
GBP 32,000 - 42,000
Hybrid working