Senior Cybersecurity Engineer
We are seeking a Senior Cybersecurity Engineer to join a growing technology and security function within a complex enterprise environment.
This is a broad, hands-on cybersecurity role combining security engineering, security operations, risk management and governance. You will play a key role in strengthening security controls across cloud, infrastructure, network and endpoint environments while supporting the organisation's ISO 27001-aligned security framework.
Key Responsibilities
- Manage and continually improve the organisation's ISMS and support ISO 27001 certification and audits.
- Identify, assess and manage information security risks and remediation plans.
- Administer and improve security across Azure, VMware, Windows Server and Active Directory.
- Manage and monitor EDR/XDR, SIEM/SOC, firewalls, WAF and vulnerability management technologies.
- Support incident response, security investigations and ongoing improvements to detection and response.
- Maintain secure firewall configurations, system hardening standards and access controls.
- Coordinate vulnerability assessments, penetration testing and remediation programmes.
- Conduct security assessments, internal audits and information classification exercises.
- Develop and test incident response and crisis management plans.
- Provide security guidance to technical teams and senior business stakeholders.
- Support security governance, reporting, awareness and wider cybersecurity initiatives.
About You
- 8+ years' experience in cybersecurity, information security, security engineering or infrastructure security.
- Strong practical experience with ISO 27001 / ISMS.
- Hands-on experience across cloud, network, endpoint and infrastructure security.
- Strong knowledge of Azure, Windows Server and Active Directory security.
- Experience with EDR/XDR, SIEM/SOC, firewalls and vulnerability management.
- Understanding of network security, OWASP, TLS/PKI, encryption and least privilege.
- Experience coordinating penetration testing and security remediation.
- Strong risk management, incident investigation and stakeholder management skills.
- Relevant certification such as CISSP, CISM, CISA, SSCP or equivalent is highly desirable.
- ISO 27001 training or practitioner experience would be advantageous.
This is an excellent opportunity for a senior security professional looking for a role with significant technical ownership while also influencing security governance, risk and compliance across a broad technology environment.
Reperio Human Capital acts as an Employment Agency and an Employment Business.