The Opportunity
We are seeking an experienced Cybersecurity Engineering & Compliance Lead to take a key role in protecting the organisation's information, systems and technology environment.
This is a senior cybersecurity position combining security engineering, operational security, risk management and compliance. You will be responsible for strengthening security controls across on-premises and cloud environments, managing cybersecurity risks, supporting regulatory and certification requirements, and helping the organisation respond effectively to evolving cyber threats.
The successful candidate will be a hands-on security professional who can operate confidently across both technical and governance environments, communicate effectively with technical and business stakeholders, and take ownership of security initiatives from planning through to completion.
Key Responsibilities
- Develop, implement and maintain information security policies, standards, procedures and controls.
- Manage and continually improve the organisation's Information Security Management System (ISMS).
- Support the ongoing maintenance of ISO 27001 certification, including audit preparation, evidence management and remediation activity.
- Maintain compliance with PCI DSS, including vulnerability scanning, assessments, penetration testing and associated remediation.
- Identify, assess, document and manage information security risks across the organisation.
- Develop and oversee risk mitigation and remediation plans.
- Conduct information classification exercises, security assessments and internal audits.
- Design, implement and administer security controls protecting the confidentiality, integrity and availability of information systems.
- Manage and improve security across cloud, infrastructure, network and endpoint environments.
- Administer and monitor EDR/XDR, SIEM/SOC, firewall, WAF and vulnerability management technologies.
- Investigate security alerts and incidents, supporting effective incident response and continually improving detection and response capabilities.
- Develop, maintain and test cybersecurity incident response and crisis management plans, including annual tabletop exercises.
- Maintain secure firewall configurations, policies and rules.
- Manage application patching and approved application compliance.
- Coordinate vulnerability scanning and ensure identified vulnerabilities are prioritised and remediated according to the organisation's risk framework.
- Provide security administration across Microsoft Azure, VMware, Windows Server and Active Directory environments.
- Develop and maintain system hardening standards and secure configuration procedures.
- Conduct periodic user access reviews and support the implementation of least-privilege principles.
- Maintain security and compliance performance metrics and reporting.
- Coordinate security testing, including network penetration testing and web application assessments.
- Chair and support information security governance forums, including preparation of agendas, minutes and actions.
- Support cybersecurity awareness, training and education initiatives across the organisation.
- Monitor changes in cybersecurity threats, technologies, legislation and industry best practice.
- Provide expert guidance to IT and business stakeholders on information security, risk, compliance, standards and security architecture.
- Work collaboratively with wider cybersecurity and corporate security teams on strategic initiatives.
- Support colleagues and the wider IT function with cybersecurity-related issues and projects.
- Participate in wider technology and business projects where security expertise is required.
Essential Experience & Technical Skills
You will ideally have:
- 8+ years' experience in cybersecurity, information security, security engineering or infrastructure security.
- Strong experience implementing and maintaining an ISO 27001-aligned ISMS.
- Practical knowledge of PCI DSS, including control implementation and compliance documentation.
- Experience performing information security and technology risk assessments.
- Strong knowledge of Windows Server and Active Directory security.
- Experience with security operations, incident management, vulnerability management, patching, log analysis and intrusion detection.
- Hands-on experience with enterprise EDR/XDR technologies.
- Experience with SIEM/SOC environments and security monitoring.
- Strong understanding of firewalls, proxies, WAF, IDPS and network security technologies.
- Experience designing and maintaining firewall rules and security policies.
- Experience administering security within Microsoft Azure, including IaaS, PaaS and SaaS environments.
- Knowledge of network security architecture, TCP/IP, the OSI model and secure remote access technologies.
- Understanding of secure development principles, OWASP vulnerabilities and least-privilege concepts.
- Knowledge of data protection, storage security and encryption.
- Experience with HTTPS, TLS and PKI.
- Experience with web server security, preferably including Microsoft IIS.
- Experience coordinating or managing penetration testing and security remediation programmes.
- Understanding of GDPR and data protection requirements.
- Experience managing technical or security-related projects.
- Strong analytical, problem-solving and incident investigation capabilities.
Qualifications & Certifications
A degree in Computer Science, Information Security, Cybersecurity or a related discipline would be advantageous.
Candidates should hold, or be actively working towards, a recognised cybersecurity qualification such as:
- CISSP
- CISM
- CISA
- SSCP
- CompTIA Security+ / SecurityX
- CCNA / CCNP Security or Cybersecurity
- Another recognised equivalent cybersecurity certification
ISO 27001 training or practitioner experience would be highly beneficial.
Personal Attributes
We are looking for someone who is:
- Passionate about cybersecurity and information protection.
- Self-motivated, organised and comfortable working with minimal supervision.
- Able to take ownership and see tasks and projects through to completion.
- Confident communicating with both technical teams and senior business stakeholders.
- Comfortable working in a fast-moving environment where priorities can change.
- Able to remain calm, analytical and decisive when dealing with security incidents or high-pressure situations.
- Naturally curious and willing to learn new technologies and environments quickly.
- A strong collaborator who enjoys sharing knowledge and supporting colleagues.
- Able to translate complex technical and security matters into clear, concise business language.
- Strong in influencing, negotiation, problem-solving and stakeholder management.
- Committed to maintaining high standards of quality, security and professional integrity.
- Fluent in written and spoken English.
What You'll Bring
This role would suit an experienced cybersecurity professional who enjoys combining hands-on technical security engineering with governance, risk and compliance.
You will have the opportunity to influence the organisation's security posture, strengthen its security framework, work across a broad technology estate and play an important role in preparing the business for an increasingly complex cyber threat landscape.
