Information Security Design Engineer
The Information Security Design and Engineering Team are responsible for the design, engineering, technical delivery, maintenance and improvements of the systems and applications for the Information Security Office. We are expected to add value by improving these tools through tuning, enhancements, and improved adoption. Working alongside the other areas of Technology and the Information Security Office, we ensure that solutions delivered meet industry best practice and compliance requirements.
As an Information Security Enginee r, you will be responsible for the development and updating of systems or products, in conformance with agreed security requirements and standards, throughout its life cycle. You will document the technical designs, implementation and tuning of a combination of security controls to balance prevention, detection, response and useability. This could involve detailed technical design, coding, or hardware prototyping, debugging and documentation.
Key Accountabilities:
To proactively protect us in engineering secure solutions from inception to retirement, reducing the risk of a cyber event impacting customers, colleagues or reputation.
Development of information security products using components, tools, techniques, and methodologies which minimise the chance of creating vulnerabilities in the products
Integration of security products into more complex systems, including cloud-based systems
Produce documentation on the products and services to guide implementers, system operators and administrators and,
Experience:
In order to succeed in this role, it is expected that you will have three or more years' experience in:
Working within information security operations and engineering functions
Development and documentation of detailed designs
Cyber security and data protection regulations
Cloud development techniques
Configuring and implementing software and hardware security components, including cryptographic solutions
Secure development standards, such as Security Development Lifecycle
'Agile' techniques and methodologies, such as SCRUM, SAFe, continuous Development, Continuous Integration and Continuous Testing
Mentoring and people development
Knowledge and experience in one or more of the following areas:
o Identify & Access Management
o Endpoint Protection
o Network Security
o Office 365 & Email Security
o Application Security
o Cloud Platform Security
o Operational Technology Security
Personal attributes:
In order to succeed in this role, it is expected that you will have:
Ability to work effectively across teams to promote information security design and best practice across the wider technology and business team.
Problem-solving and logical thinking
Strong influencing skills, working with other teams and bringing experience from other technologies in applying remediation.
Good time management, presentation and communication skills are essential, as is the ability to work in a high-pressure environment.
The ability to balance local needs vs. organisation wide strategy to make informed decisions
Preferred
Degree level or extensive relevant experience
Have achieved an industry recognised certification, such as CCSP, CISSP, a BCS c ertificate in information security management
Hold or be capable of gaining SC Clearance