Security Engineer
At CV-Library, we have a simple vision: to help the world to work and we are looking for exceptional and talented people to help us realise this vision in both UK and overseas markets.
We are in a period of focused internal investment, following a year of key strategic acquisitions and significant investment across all parts of the business, from Tech and Data to People and HR, there's never been a more exciting time to join us or a better place to grow your career!
The Role
Hours: Monday-Friday, 9:00-17:30
Location: Fleet
Working Pattern: Hybrid - 3 days a week on site
This is a security role built for someone who wants to own the threat, not just log it. As Security Engineer, you'll be the person who understands what's actually at risk across a modern Cloud native microservice platform and our internal IT estate, from SIEM alerts to Microsoft 365 endpoint security, and who sets the priorities that matter. You won't be buried in compliance paperwork. You'll direct a capable Platform Ops team on remediation while you stay focused on the threat picture, the tooling and the DevSecOps thinking that keeps CV-Library ahead of it.
You'll report directly to the Platform & Service Operations Manager, with a genuine mandate to shape how security is done, not just document it. Compliance still matters, and you'll keep ISO 27001 documentation and audit evidence in good shape as you go, but it's the by-product of doing security well, not the job itself.
Responsibilities:
- Own the day-to-day management of security alerts, investigations and incidents across CV-Library's technology estate
- Monitor emerging cyber threats and threat intelligence, assessing potential risks and recommending improvements to security controls
- Lead the initial response to security incidents, coordinating containment and remediation activities with relevant technical teams
- Maintain incident records, conduct post-incident reviews and ensure lessons are learned are embedded into processes, tooling and controls
- Manage and continuously improve the organisation's security tooling, including SIEM, endpoint protection, vulnerability management and cloud security solutions
- Take ownership of endpoint and Microsoft 365 security, including device security, conditional access policies and identity protection controls
- Define and maintain security standards and guardrails for cloud infrastructure and software delivery, working closely with Platform DevOps teams
- Manage identity and access management processes, supporting user provisioning, access reviews and least-privilege principles
- Act as the security subject matter expert, providing guidance on infrastructure, platform and application changes
- Oversee the vulnerability management lifecycle, ensuring security weaknesses are identified, prioritised and remediated effectively
- Coordinate external penetration testing activities and track remediation actions through to completion
- Maintain security documentation, policies and audit evidence, supporting ongoing ISO 27001 compliance and certification requirements
- Apply GDPR and data protection principles to ensure security controls, processes and documentation meet regulatory expectations
- Support supplier and third-party security assessments, helping to identify and manage external risks
- Assess the secure use of AI technologies across the business and champion a strong security culture by promoting best practice across best technology and non-technical teams
What we're looking for
- Strong technical knowledge of security tools, frameworks and best practice
- Solid understanding of cloud-native infrastructure (AWS, Kubernetes/EKS) sufficient to assess and prioritise risk and to direct Platform Ops on remediation, without owning infrastructure changes directly
- Experience with penetration testing engagement and vulnerability management processes
- Understanding of endpoint protection technologies and policy configuration, including Microsoft 365 security tooling (e.g. Defender, Intune, Conditional Access)
- Working knowledge of Identity and Access Management principles
- Strong incident response and threat intelligence skills, including SIEM-based monitoring and triage
- Familiarity with security accreditations such as ISO 27001 and what they require operationally
- Working knowledge of UK GDPR and data protection principles, particularly as they relate to security control and audit documentation
- Excellent communication skills, able to convey security matters clearly to both technical and non-technical audiences
We are actively committed to promoting a fully diverse and inclusive workforce and we welcome applications for this role from all candidates who meet the key requirements.
Please do not hesitate to get in touch should you require any reasonable adjustments to assist with your application.
Other jobs of interest...
Perform a fresh search...
-
Create your ideal job search criteria by
completing our quick and simple form and
receive daily job alerts tailored to you!