Cyber Security Engineer | Financial Services

Location London
Discipline: Cyber Security, Information & Cyber Security
Job type: Permanent
Salary: £up to 110,000 per annum

A permanent opportunity for a Cyber Security Engineer is open at a prestigious Financial Services company based in Central London.

Supporting the Cyber Security Manager, this role will execute the company’s cyber security strategy, manage cyber security tools, respond to alerts, threat hunting, conduct security assessments, and creating staff training programs. 

Key Responsibilities

  • Drive continuous improvement of cyber security tools, configurations, and identify opportunities for enhancement.

  • Monitor and respond to security alerts from various sources, including tools and email reports.

  • Perform threat hunting to investigate and address the root causes of security alerts and vulnerabilities.

  • Design and implement training programs and phishing simulations to assess staff awareness and improve security practices.

  • Lead security assessments of third-party tools, networks, hosts, and applications, including tasks like packet captures and service enumeration.

  • Facilitate external penetration testing and ensure that mitigation measures are implemented.

  • Lead due diligence on third-party services, supporting business decisions with security assessments.

  • Review and update security policies and procedures annually.

Skills and Experience

  • 5+ years of experience in a Cyber Security Engineer or a similar role

  • Proficient in scripting with Bash, Python, or PowerShell

  • Relevant cyber security certifications such as CEH, CISSP, OSCP, or equivalent

  • Strong background in Linux and Windows system administration

  • Solid understanding of networking fundamentals (TCP/IP, routing, switching) and underlying internet technologies

  • Strong grasp of vulnerability assessments, incident management, and threat intelligence practices

  • Broad knowledge across server, desktop, storage, network, database, firewall, SaaS, and virtual machine technologies

  • Knowledge of email security controls and common attack vectors such as phishing and insider threats

  • Familiarity with endpoint protection, anti-malware solutions, and vulnerability scanning tools