S

Cyber Security Engineer

Salfords
3 hours ago
Full-time
On-site
RH1, Salfords, Surrey
£500 - £600 GBP daily
Security
Cybersecurity Engineer

Job Summary

Supports the handover of existing security tools, including oversight and management of access control, technical management of security materials such as cryptographic keys, passwords and certificates, as well as additional security monitoring, vulnerability management, tool maintenance and configuration.

The role will also provide knowledge transfer and training to the successor operator’s security architecture staff.

Essential Job Duties and Responsibilities

Ensure RCC Handover project objectives are supported by appropriate cybersecurity requirements.

Define, document and perform technical changes in security tooling to support RCC Handover.

Lead cybersecurity assurance within RCC Handover change boards and design gateways.

Ensure appropriate security support processes are followed by the RCC Handover team.

Ensure the customer and successor operator understand the technical impact of RCC Handover tasks.

Provide input into other cybersecurity, contingency planning and related RCC Handback activities.

Create and update technical documentation for security tools, processes and information assets as directed by the RCC Handover leadership team.

Assess RCC Handover change control requests for potential impact on existing security mechanisms and ensure any potential compromise or weakening of security controls is minimised.

Perform security monitoring and vulnerability management of information assets in scope of RCC Handover tasks, supporting existing business-as-usual teams.

Perform handover of security secret materials, including cryptographic keys and certificates, devices and access control credentials to the customer and/or successor operator.

Provide reporting to the RCC Handback leadership team.

May be required to work across customer, TfL, successor operator sites and data centres.

Minimum Job Requirements

Qualifications

Essential

Certification as an Information Security professional, for example:

IISP

CISA

CISM

CISSP

CCSP

ISA

Desirable

University degree in a numerate subject such as Computer Science, Mathematics, Engineering or Natural Sciences.

Information privacy/data protection certifications such as CIPP/E and CIPM.

HMG IA qualifications / CLAS.

CREST-registered penetration tester and/or security architect.

ITIL v3, PRINCE2 Foundation and/or TOGAF.

Security, IT infrastructure or networking vendor certifications.

Skills, Experience and Knowledge

Essential

Strong experience taking a leading role in the establishment and implementation of security architecture, policies and procedures.

Good understanding of enterprise-scale security management processes and infrastructure.

Experience working with current IT security standards and regulations such as PCI-DSS, ISO 27001 and UK data protection legislation.

In-depth understanding of information security control tools, for example:

Splunk Cloud

CrowdStrike

Qualys

Trellix

Tripwire

Cisco IPS

F5

Centrify

Experience working with enterprise IT infrastructure and technologies such as Microsoft Windows Server, Cisco and Linux.

Desirable

Experience within transactional revenue, embedded systems, smartcards and mobile payment systems.

Knowledge or experience of security architecture across major public cloud services such as:

Microsoft Azure

Amazon Web Services

Google Cloud

Cloud Access Security Brokers

Knowledge of cryptographic services, products and HSM devices.

Knowledge of wider security, audit, risk and compliance standards including:

PCI-P2PE

PCI-POI-PTS

ISO 27701

ISO 27005

ISO 31000

NIST

GDPR

Governance, Risk and Compliance tools

Experience with quality management systems and external audit standards such as ISO 9001