At CV-Library, we have a simple vision: to help the world to work and we are looking for exceptional and talented people to help us realise this vision in both UK and overseas markets.
We are in a period of focused internal investment, following a year of key strategic acquisitions and significant investment across all parts of the business, from Tech and Data to People and HR, there’s never been a more exciting time to join us or a better place to grow your career!
The Role
Hours: Monday-Friday, 9:00-17:30 Location: Fleet Working Pattern: Hybrid – 3 days a week on site
This is a security role built for someone who wants to own the threat, not just log it. As Security Engineer, you’ll be the person who understands what’s actually at risk across a modern Cloud native microservice platform and our internal IT estate, from SIEM alerts to Microsoft 365 endpoint security, and who sets the priorities that matter. You won’t be buried in compliance paperwork. You’ll direct a capable Platform Ops team on remediation while you stay focused on the threat picture, the tooling and the DevSecOps thinking that keeps CV-Library ahead of it.
You’ll report directly to the Platform & Service Operations Manager, with a genuine mandate to shape how security is done, not just document it. Compliance still matters, and you’ll keep ISO 27001 documentation and audit evidence in good shape as you go, but it’s the by-product of doing security well, not the job itself.
Responsibilities:
Own the day-to-day management of security alerts, investigations and incidents across CV-Library’s technology estate
Monitor emerging cyber threats and threat intelligence, assessing potential risks and recommending improvements to security controls
Lead the initial response to security incidents, coordinating containment and remediation activities with relevant technical teams
Maintain incident records, conduct post-incident reviews and ensure lessons are learned are embedded into processes, tooling and controls
Manage and continuously improve the organisation’s security tooling, including SIEM, endpoint protection, vulnerability management and cloud security solutions
Take ownership of endpoint and Microsoft 365 security, including device security, conditional access policies and identity protection controls
Define and maintain security standards and guardrails for cloud infrastructure and software delivery, working closely with Platform DevOps teams
Manage identity and access management processes, supporting user provisioning, access reviews and least-privilege principles
Act as the security subject matter expert, providing guidance on infrastructure, platform and application changes
Oversee the vulnerability management lifecycle, ensuring security weaknesses are identified, prioritised and remediated effectively
Coordinate external penetration testing activities and track remediation actions through to completion
Maintain security documentation, policies and audit evidence, supporting ongoing ISO 27001 compliance and certification requirements
Apply GDPR and data protection principles to ensure security controls, processes and documentation meet regulatory expectations
Support supplier and third-party security assessments, helping to identify and manage external risks
Assess the secure use of AI technologies across the business and champion a strong security culture by promoting best practice across best technology and non-technical teams
What we’re looking for
Strong technical knowledge of security tools, frameworks and best practice
Solid understanding of cloud-native infrastructure (AWS, Kubernetes/EKS) sufficient to assess and prioritise risk and to direct Platform Ops on remediation, without owning infrastructure changes directly
Experience with penetration testing engagement and vulnerability management processes
Understanding of endpoint protection technologies and policy configuration, including Microsoft 365 security tooling (e.g. Defender, Intune, Conditional Access)
Working knowledge of Identity and Access Management principles
Strong incident response and threat intelligence skills, including SIEM-based monitoring and triage
Familiarity with security accreditations such as ISO 27001 and what they require operationally
Working knowledge of UK GDPR and data protection principles, particularly as they relate to security control and audit documentation
Excellent communication skills, able to convey security matters clearly to both technical and non-technical audiences
We are actively committed to promoting a fully diverse and inclusive workforce and we welcome applications for this role from all candidates who meet the key requirements.
Please do not hesitate to get in touch should you require any reasonable adjustments to assist with your application.
CV-Library is the UK's leading independent job board, helping companies of all sizes and industries to hire faster, for less. Known for its market-leading innovations and inspired hiring solutions, CV- Library is an award-winning business with a 5* Trustpilot rating, the highest rating in the indust...
All Job Ads are subject to GrabJobs’s Terms of Service. We allow users to flag postings that may be in violation of those terms. Job Ads may also be flagged by GrabJobs moderation team. However, no moderation system is perfect, and flagging a posting does not ensure that it will be removed.
Be the first to receive the latest Others Full-Time Jobs in the UK.
Setup your job alert:
By activating job alerts, I agree to GrabJobs Terms & Privacy Policy. I can unsubscribe to job alerts anytime.
Skip
GrabJobs is the no1 job portal in the UK, connecting you to thousands of jobs fast!
Find the best jobs in the UK, apply in 1 click and get a job today!