- Company Name
- Galliford Try
- Job Title
- Senior Information Security Engineer
- Job Description
-
Job title: Senior Information Security Engineer
Role Summary:
Lead the design, deployment, and maintenance of the organisation’s cybersecurity strategy. Partner with internal stakeholders and third‑party security providers to safeguard digital assets through threat detection, vulnerability management, incident response, and continuous improvement of security tools and policies.
Expectations:
- Maintain a robust, compliant security posture that aligns with ISO 27001, Cyber Essentials, UK GDPR, and NIST guidance.
- Reduce the mean time to detect and contain incidents; provide actionable risk mitigation.
- Deliver clear, audit‑ready documentation and evidence of controls, tools, and processes.
- Mentor junior staff and foster a security‑aware culture across the business.
Key Responsibilities:
- Operate and monitor SOC/SIEM environments; analyse alerts for compromise.
- Conduct regular vulnerability scans, risk assessments, and penetration test coordination.
- Lead or support incident investigations, incident containment, and post‑incident reporting.
- Draft, review, and enforce security policies, standards, and procedures.
- Administer and optimise Microsoft Azure, Entra ID, Microsoft 365, Defender stack, and endpoint protection solutions.
- Plan and run security awareness campaigns, phishing simulations, and training materials.
- Support compliance audits, prepare evidence, and facilitate internal/external audit processes.
- Advise on emerging threats, recommend tool and process enhancements, and document changes.
Required Skills:
- 5+ years in information security or related technical roles.
- Experience managing outsourced SOC/SIEM services; hands‑on incident response and vulnerability management.
- Proficiency with Microsoft 365, Azure security controls; knowledge of AWS/GCP desirable.
- Strong documentation, communication, and stakeholder engagement abilities.
- Ability to prioritise, adapt, and manage multiple concurrent projects.
- Ethical mindset and commitment to continuous learning.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Certifications such as CISSP, CISA, CRISC, ISO 27001 Lead Implementer/Lead Auditor, CEH, or Microsoft Certified: Azure Security Engineer Associate preferred.
Leicester, United kingdom
On site
Senior
11-12-2025