Security Engineer
This role sits at the intersection of security engineering, security operations, and compliance. It focuses on threat response, DLP and identity controls, vulnerability management, audit requirements, compliance automation, and security programme operations.
Responsibilities
- Monitor, triage, and respond to security alerts and incidents across cloud, endpoint, and SaaS environments.
- Own and extend Data Loss Prevention controls, including policy tuning, coverage analysis, and endpoint rollout.
- Manage device compliance and identity workflows through MDM platforms and REST APIs.
- Run vulnerability scanning, track remediation, and contribute to board-level risk reporting.
- Translate SOC 2, ISO 27001, PCI DSS, and DORA requirements into technical controls, evidence processes, and automated checks.
- Operate the Bug Bounty and Responsible Disclosure programme.
- Build scripts and lightweight tools to automate security operations and improve audit evidence quality.
Requirements
- 2 to 5 years of experience in security engineering, security operations, or an equivalent hands-on technical security role.
- Practical experience with cloud security, endpoint and MDM tooling, DLP platforms, identity and access management, and SIEM or alerting tools.
- Scripting ability to automate workflows and integrate with REST APIs.
- Working knowledge of SOC 2, ISO 27001, PCI DSS, or DORA.
- Ability to produce control narratives, incident summaries, and stakeholder-facing documentation.
- Ability to work across hands-on engineering, compliance, and documentation.
- Experience with Bug Bounty or Vulnerability Disclosure programmes is a nice to have.
- Exposure to Security Trust Centre or external-facing security documentation is a nice to have.
- Familiarity with DORA implementation is a nice to have.