Security Engineer enhancing security platform and controls at TMGM, an expanding CFD and Forex broker. Collaborate with teams to improve security measures in cloud and on-premises environments.
Responsibilities
Operate and fine-tune EDR, ensuring high visibility and timely response to detections.
Investigate alerts, triage incidents, and coordinate remediation with IT and engineering teams.
Develop and maintain detection rules, response playbooks, and operational dashboards.
Run regular vulnerability scans across endpoints, servers, and cloud workloads.
Prioritise findings based on exploitability and asset criticality.
Work with system owners to track remediation progress and verify fixes.
Review and improve AWS configurations using AWS tools or CNAPP / CSPM monitoring tools (e.g., Wiz, Orca)
Support secure architecture and IaC practices (Terraform, CloudFormation) with dev teams.
Automate checks and alerting for misconfigurations and policy violations.
Support developers on secure coding practices and pipeline integration (e.g., Snyk).
Review secrets management, API credential handling, and CI/CD pipeline security.
Implement and maintain least privilege and MFA policies across systems.
Assist with SSO/SCIM integrations (e.g., Entra ID, 1Password, Cloudflare Zero Trust).
Work alongside IT Operations and Cloud teams to deploy, harden, and monitor security tools.
Participate in incident response exercises, phishing simulations, and post-incident reviews.
Contribute to process documentation and internal knowledge base (e.g., runbooks, playbooks).
Requirements
4–6 years of hands-on security experience, ideally in endpoint protection, cloud security, or vulnerability management.
Strong working knowledge of AWS security services, IAM, and network fundamentals.
Practical experience with EDR tools (CrowdStrike, Defender, etc.) and vulnerability scanners (Qualys, Tenable, etc.).
Solid understanding of incident response, detection engineering, and access control principles.
Exposure to security frameworks (ISO 27001, SOC 2, NIST) is a plus, but not mandatory.
Clear communicator who can explain security findings to both technical and non-technical teams.
Benefits
Hybrid working arrangement - 2 Days of remote work per week
Opportunities for enriching career growth, including exposure to regional contexts
Complimentary snacks and beverages available in the office pantry
Cyber Security Architect responsible for IT security compliance and cyber - risk management at a Swiss utility firm. Engaging with cross - functional teams to implement 'Secure - by - design' strategies.
Information Security Officer ensuring cybersecurity at an IT service provider for food and beverage sector. Developing strategies and overseeing security protocols while reporting to management.
Head of Information Security at Aurora shaping security strategy and governance in a software - focused global business. Leading security efforts to ensure resilience and compliance across operations.
Senior Security Engineer specializing in penetration testing and security strategies for fintech. Collaborating with teams to enhance security for AI applications and financial systems.
Principal Cyber Security Engineer for Identity Access Management at MSK managing identity solutions and advanced identity platforms. Partnering with stakeholders to align identity strategy and lead IAM initiatives.
Join The Missing Link as a Security Engineer, leveraging 3 - 4 years of IT Security experience. Lead projects in a collaborative environment with a focus on innovation and impact.
Engineer in Health, Safety and Environment for ArianeGroup focusing on industrial risk management. Involves audits, assessments, and safety training participation.
Senior Product Security Engineer at Red Hat focusing on security and compliance for digital sovereign products while collaborating across global teams and enhancing automation.
Security Engineer safeguarding K - 12 student data in several locations for EduTech startup. Designing secure software systems and ensuring data protection to comply with privacy standards.
Security Engineer focusing on data protection and privacy for Kira Learning's educational technology. Safeguarding K - 12 student data while collaborating with engineering teams on secure software development.