Cloud Security Engineer
$50,000–$70,000 year
HybridManchester, England, United Kingdom
Job Summary
Drive end-to-end vulnerability management by running scans across systems, networks, and applications, prioritizing risks, and tracking remediation to closure. Lead security alert responses by triaging issues, coordinating with the wider team across time zones, and documenting post-incident reviews. Maintain daily office operations as the sole on-site IT support, managing hardware, software, accounts, and new starters. Take turns on the on-call rota to respond to critical incidents outside standard hours. This role requires NPPV3 and SC security clearances and is based in Manchester, UK, with three days on-site.
Required Qualifications
- Applicants must be authorized to work for any employer in the country in which the role is being hired
- We are unable to sponsor or take over sponsorship of an employment visa at this time
- minimum of 5 years of experience
- ideally with a strong focus on vulnerability and threat research and management
- knowing which vulnerabilities to escalate
- how to run an incident calmly under pressure
- when to ask for help
- Solid all-round IT support skills across Windows environments, networking, and common business tools
- Familiarity with vulnerability scanners
- endpoint protection
- SIEM tooling
- awareness of UK data protection requirements and frameworks such as Cyber Essentials or ISO 27001
- comfortable joining an on-call rota
- collaborating across time zones
- required to obtain and maintain NPPV3 (Non-Police Personnel Vetting Level 3) and SC (Security Check) clearance
- minimum of 5 years' recent UK residency
- on-site 3 days per week
- Engage in appropriate use of the company's electronic information resources
- Become knowledgeable about and follow relevant security policies and guidelines
- Protect the resources under their control, such as passwords, computers, and data that they create, receive, or download
- Promptly report security-related incidents and violations
- responding to official reports of security incidents involving their systems or accounts
Desired Qualifications
- Familiarity with vulnerability scanners, endpoint protection, and SIEM tooling is a welcome bonus
- awareness of UK data protection requirements and frameworks such as Cyber Essentials or ISO 27001 is a welcome bonus
- Humble, open, and curious
- Calm and decisive under pressure
- Self-directed and dependable
- A clear and approachable communicator
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.