Senior Security Engineer

Kainos

Hurley

On-site

GBP 90,000 - 120,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Kainos in the United Kingdom is seeking a Senior Security Engineer to embed security across cloud-based software delivery. You will work with multi-disciplinary Agile teams to design and implement secure solutions and practice DevSecOps throughout the SDLC.

In this role you will collaborate with development and cloud platform teams, drive threat modelling, vulnerability management, and security testing while translating findings into actionable security stories for delivery teams.

Qualifications

  • Experience implementing application security or Cloud platform security.
  • Experience in Defence Sector.
  • Active Security Clearance.
  • Understanding of web application security.
  • Knowledge of cryptography for encryption in-transit, at-rest, hashing and signatures.
  • Understanding threat modelling, vulnerability management, application security testing, and penetration testing.
  • Experience integrating security tools into the SSDLC.
  • Experience with version control and scripting or programming or IaC to automate tasks.
  • Ability to convey security issues to technical and non-technical audiences.

Responsibilities

  • Collaborate with development and cloud platform teams to plan and prioritise security requirements as part of the SSDLC.
  • Recommend security best practices for cloud platforms and automating compliance with cloud security baselines (e.g. CIS Benchmarks).
  • Implement automated security tooling in CI pipelines to validate security requirements and identify issues.
  • Work with external organisations to plan, scope and facilitate penetration tests.
  • Review outputs from security tools and security practices.
  • Filter and prioritise results into security stories that are understood by delivery teams.
  • Verify the implementation of security principles and architectural patterns.
  • Drive adoption of cyber security practices within Agile delivery teams.

Skills

Application security
Cloud security
Threat modelling
Vulnerability management
Penetration testing
CI/CD security tooling
Strong communication

Tools

Static analysis tools
Dynamic analysis tools
Git
Scripting languages
Terraform/ IaC templates

Job description

embedding security practices (e.g. vulnerability management, threat modelling etc.) and automating security artifact generation (e.g. secret scanning, container security, SAST, DAST etc.). You will provide subject matter expertise in application security or cloud security sharing knowledge on threats and vulnerabilities, identifying appropriate security controls, and increasing cyber security awareness within teams.

Your key responsibilities will include:

  • Daily collaboration with the application development and cloud platform teams to plan and prioritise security requirements as part of the secure software development lifecycle (SSDLC).
  • Recommending security best practices for cloud platforms and automating compliance with cloud security baselines (e.g. CIS Benchmarks).
  • Implementation of automated security tooling (e.g. within a Continuous Integration (CI) pipeline) to validate security requirements and identify potential issues.
  • Working with external organisations to plan, scope and facilitate penetration tests.
  • Reviewing the outputs from security tools and security practices.
  • You will filter and prioritise these into security stories that can be understood and actioned by the delivery teams.
  • Verifying the implementation of security principles, architectural patterns, and requirements.
  • Driving the adoption of cyber security practices (e.g. vulnerability management, threat modelling etc.) within Agile delivery teams.

Putting people first & developing others Youll help coach and develop more junior members of the team.

Minimum (essential) requirements
  • Experience of implementing application security or Cloud platform security.
  • Experience in Defence Sector
  • Active Security Clearance
  • A detailed understanding of web application security.
  • An understanding of modern cryptography and its application for encryption in-transit, encryption at-rest, hashing and digital signatures.
  • An understanding of security practices such as threat modelling, vulnerability management, application security testing, and penetration testing.
  • Experience of integrating application security tools (e.g. static analysis, dynamic analysis etc.) into the SSDLC.
  • Experience of using modern version control systems (e.g. git) and either a scripting language (e.g. Bash, Powershell etc.), or a programming language (e.g. Python, Java, .NET, JS etc.), or an Infrastructure as Code language (e.g. Terraform, ARM Templates, Ansible etc.) to automate tasks.
  • The ability to convey security issues to technical and non-technical people.
Desirable
  • An industry recognised qualification in Cyber Security.
  • AWS or Azure mid-level certifications.
  • Participation in the cyber security community (e.g. OWASP, HackTheBox, CTFs etc.).
  • Experience working with agile software development methodologies (e.g. Scrum or Kanban).
Embracing our differences

At Kainos, we believe in the power of diversity, equity and inclusion. We are committed to building a team that is as diverse as the world we live in, where everyone is valued, respected, and given an equal chance to thrive. We actively seek out talented people from all backgrounds, regardless of age, race, ethnicity, gender, sexual orientation, religion, disability, or any other characteristic that makes them who they are. We also believe every candidate deserves a level playing field. Our friendly talent acquisition team is here to support you every step of the way, so if you require any accommodations or adjustments, we encourage you to reach out. We understand that everyone's journey is different, and by having a private conversation we can ensure that our recruitment process is tailored to your needs.

TPBN1_UKTJ

hackajob is partnering directly with Kainos to hire for this role.

Join Kainos and Shape the Future At Kainos, were problem solvers, innovators, and collaborators - driven by a shared mission to create real impact. Whether were transforming digital services for millions, delivering cutting-edge Workday solutions, and ...

As a Senior Security Engineer, you will work in close collaboration with our technology teams to design and implement secure, cloud-based software solutions for our clients. Working as part of a multi-disciplinary Agile team, you will implement DevSecOps practices throughout the software development lifecycle.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Kainos • Birmingham

On-site
GBP 80,000 - 120,000
Senior Security Architect
Senior Security Architect

Kainos • Greater London

On-site
GBP 75,000 - 100,000
Lead Security Engineer
Lead Security Engineer

Kainos • Birmingham

On-site
GBP 90,000 - 120,000
Cloud Security Engineer
Cloud Security Engineer

Kainos • Budock Water

On-site
GBP 50,000 - 70,000
Cloud Security Engineer
Cloud Security Engineer

Kainos • Birmingham

On-site
GBP 50,000 - 70,000
Cloud Security Engineer
Cloud Security Engineer

Kainos • Derry/Londonderry

On-site
GBP 70,000 - 100,000
Security Architect
Security Architect

Kainos • Budock Water

On-site
GBP 60,000 - 80,000
Security Architect
Security Architect

Kainos • Greater London

On-site
GBP 70,000 - 90,000
Security Architect
Security Architect

Kainos • Birmingham

On-site
GBP 60,000 - 90,000
Cloud Security Engineer
Cloud Security Engineer

Kainos • Belfast

On-site
GBP 50,000 - 75,000