About the role
SecureGrid Technologies is seeking a Senior Cybersecurity Engineer to design, implement, and continuously improve security controls across its technology environment. The role will work closely with security operations, engineering, cloud, infrastructure, and product teams to identify and mitigate security risks and strengthen the organisation's overall security posture. The successful candidate will contribute to security architecture, vulnerability management, threat detection, incident response, and secure engineering practices. Success will be measured through effective risk reduction, reliable security controls, timely remediation, and strong collaboration across technical teams.
Benefits & perks
Health Insurance
Private healthcare coverage supporting employees' physical and mental wellbeing.
Flexible Work
Hybrid working arrangements with flexibility around location and working hours.
Learning & Budget
Dedicated budget for cybersecurity certifications, technical training, and professional development.
Wellness / Stipend
Wellbeing allowance supporting approved health, fitness, and wellness activities.
Paid Time Off
Generous paid annual leave to support rest and personal commitments.
Retirement Plan
Employer-supported workplace pension scheme with employee contribution options.
- 01Design, implement, and maintain cybersecurity controls across cloud, infrastructure, applications, and corporate systems.
- 02Conduct security assessments, vulnerability analysis, and technical risk reviews.
- 03Identify security weaknesses and work with engineering teams to develop and implement remediation plans.
- 04Support threat detection, investigation, and incident response activities.
- 05Develop and improve security monitoring, alerting, and detection capabilities.
- 06Partner with engineering and DevOps teams to integrate security into development and deployment workflows.
- 07Review cloud and infrastructure configurations for security risks and compliance requirements.
- 08Contribute to security architecture and technical design reviews for new systems and services.
- 09Develop and maintain security documentation, standards, procedures, and technical guidelines.
- 10Monitor emerging cybersecurity threats and recommend appropriate improvements to security controls.
- 11Support security testing, penetration testing activities, and remediation tracking.
- 12Provide technical guidance to engineering teams and contribute to cybersecurity knowledge sharing.
What we evaluate against.
Product Judgment & Prioritisation
Must have
- Design and implement effective cybersecurity controls across cloud, infrastructure, applications, and enterprise systems.
- Identify, assess, and prioritise technical security risks based on likelihood, impact, and business context.
- Develop practical remediation plans and work with engineering teams to reduce identified security risks.
Nice to have
- Security findings are documented with clear severity, impact, and remediation recommendations.
- Identified vulnerabilities are remediated within agreed priorities and timelines.
- Security controls demonstrate measurable improvement in the organisation's security posture.
AI & Technical Fluency
Must have
- Demonstrate strong understanding of cloud, infrastructure, networking, identity, and application security principles.
- Evaluate technical architectures and configurations for security weaknesses and design risks.
- Apply secure engineering practices across cloud environments, development pipelines, and production systems.
Nice to have
- Cloud and infrastructure security risks are identified proactively.
- Security recommendations are technically feasible and aligned with engineering constraints.
- Security controls are incorporated into system and application architecture decisions.
User & Workflow Insight
Must have
- Investigate security alerts and potential threats using appropriate security monitoring and analysis techniques.
- Support incident response activities including investigation, containment, remediation, and post-incident review.
- Develop and improve security detection capabilities based on emerging threats and observed attack patterns.
Nice to have
- Security alerts are investigated using documented and repeatable processes.
- Incident response activities are completed within agreed response objectives.
- Detection rules and monitoring capabilities are continuously improved based on lessons learned.
Experimentation, Evaluation & Learning
Must have
- Automate repeatable security tasks and controls where practical to improve efficiency and consistency.
- Evaluate security tools, technologies, and controls using measurable technical and operational criteria.
- Continuously develop knowledge of emerging threats, vulnerabilities, cloud security practices, and defensive technologies.
Nice to have
- Manual security activities are identified and converted into repeatable or automated processes where appropriate.
- Security tools and controls are evaluated using documented criteria and evidence.
- New security knowledge is incorporated into technical controls and engineering practices.
Cross-Functional Product Delivery
Must have
- Partner effectively with engineering, DevOps, cloud, product, and security operations teams to deliver security improvements.
- Translate security requirements into clear and actionable technical tasks.
- Manage security dependencies, risks, and remediation activities across multiple technical teams.
Nice to have
- Security initiatives are delivered against agreed priorities and timelines.
- Engineering teams have clear understanding of security requirements and remediation actions.
- Security risks and dependencies are communicated and escalated appropriately.
Team Structure
Cross-functional team working with recruitment, hiring managers, security teams, and business stakeholders.
Operating Rhythm
Weekly recruitment planning, regular candidate reviews, and scheduled hiring updates.
Collaboration Style
Highly collaborative approach with shared ownership across recruitment and hiring teams.
Communication
Clear, concise, and timely communication with candidates, hiring managers, and stakeholders.
Decision Making
Data-informed hiring decisions based on candidate assessments, interview feedback, and role requirements.
Documentation Culture
Security findings, architecture decisions, controls, procedures, and remediation activities are documented clearly.
Innovation
Encourages new ideas, advanced security solutions, and continuous improvement.
Transparency
Promotes clear communication and openness with employees and clients.
Ownership
Employees take responsibility for their work, decisions, and security outcomes.
Collaboration
Teams work together to solve complex cybersecurity challenges.
Learning Culture
Employees are encouraged to continuously improve their cybersecurity knowledge and skills.
Feedback
Employees are encouraged to share feedback and suggestions for improving processes.
First 30 days
Build a strong understanding of SecureGrid's technology environment, security architecture, key applications, cloud infrastructure, security controls, and current risk profile. Establish relationships with engineering, DevOps, cloud, security operations, and product teams. Review existing vulnerabilities, security processes, monitoring capabilities, and remediation priorities, and identify immediate security improvement opportunities.
90 days
Deliver measurable improvements to priority security risks and establish clear remediation plans for identified vulnerabilities. Strengthen security monitoring and detection capabilities, contribute to architecture and technical security reviews, improve security documentation, and establish effective collaboration practices with engineering and security teams.
Outcomes
Strengthen SecureGrid's overall security posture through effective security engineering, proactive risk management, improved detection and response capabilities, and secure-by-design engineering practices. Reduce high-priority security risks, improve remediation effectiveness, automate repeatable security processes, and establish scalable security controls that support the company's continued growth while maintaining strong operational and compliance standards.