Security Engineer

Douglas, Isle of Man
1 month ago
Create job alert

Overview

Our leading Douglas-based Finance Sector Client is expanding its Finance Team as they progress an ambitious transformation programme. As they evolve the technology organisation, they require an experienced Security Engineer.

Note - this role is based on the Isle of Man, so requires candidates to either be based on the island currently or be open to relocation.

Reporting to the Head of IT Security, the Security Engineer will assist with the translation of the company's Information Security policies and standards into practical operational procedures. You will work as part of the IT Security Team in areas including the design, implementation and maintenance of robust security measures across network and cloud environments, ensuring protection against potential threats, adherence to industry standards, and proactive incident response. This will include providing security consultancy services to the Change Team.

In this role you will

  • Ensure continual alignment of Information Security Policies with industry standards, regulatory requirements, and evolving cyber threats

  • Develop and communicate an effective strategy for the implementation of Information Security Policies across all departments and systems within the organisation

  • Establish mechanisms to regularly monitor and, measure compliance with Information Security Policies, addressing non-compliance issues

  • Maintain updated documentation, providing easy access to policies, guidelines, and procedures for all staff members

  • Establish a robust mechanism to ensure alignment with relevant Information Security Frameworks (e.g., ISO 27000 series, NIST, etc.), mapping organisational policies and practices to the framework's requirements

  • Conduct periodic internal assessments to evaluate adherence to Information Security Frameworks and compliance standards, driving continuous improvement and implement corrective actions based on assessment findings

  • Stay updated with industry trends, best practices, regulatory standards and amendments in Information Security Frameworks

  • Develop strategic plans outlining security objectives and domain roadmaps for network and Cloud environments aligned with organisational goals

  • Develop and implement security focused Architecture Building Blocks (ABBs) and Solution Building Blocks (SBBs) in collaboration with the Architecture team

  • Ensure adherence to industry best practices, regulatory standards, and internal security policies across network and Cloud environments

  • Develop and implement incident response plans specific to network and Cloud security incidents, outlining clear protocols for detection, containment, and recovery

  • Identify and establish partnerships with external security entities, including vendors, consultants, industry groups, or security forums

  • Regularly assess the performance and alignment of external security partners with organisational security objectives

  • Establish channels for continuous intelligence gathering from external partners regarding emerging threats, vulnerabilities, and best practices

  • Foster an environment of knowledge sharing and cooperation to leverage expertise from external entities

  • Develop a comprehensive framework for assessing the security posture of Material IT Suppliers, outlining assessment criteria, methodologies, and evaluation metrics

  • Working with the Head of IT Service, establish mechanisms to verify and validate the compliance of material IT suppliers with agreed-upon security standards, contractual obligations, and regulatory requirements

  • Conduct thorough assessments to identify security risks associated with material IT suppliers, considering factors like data handling, access controls, and compliance

  • Implement tools or systems for continuous monitoring of security practices and performance of material IT suppliers

  • Develop a standardised framework for conducting comprehensive risk assessments across the organisation's systems, applications, and infrastructure

  • Conduct periodic risk assessments to identify, analyse, and prioritise potential risks and threats to the organisation's assets and operations

  • Develop and implement risk mitigation strategies based on the findings from risk assessments, vulnerability testing, and penetration testing reports

  • Organise and oversee regular vulnerability assessments and penetration testing activities to identify weaknesses and potential entry points for cyber threats

  • Develop and maintain incident response plans aligned with identified risks and potential threats

    The ideal candidate for the role of Security Engineer will have:

    • Hold a degree in Computer Science, Information Security, or related field (or equivalent experience)

    • Advanced certifications (or working towards such a certification) such as CISSP, CISM, or equivalent are preferred

    • 5+ years in network and / or Cloud security roles, demonstrating progressive responsibility

    • Proven experience in designing and implementing security solutions in network and Cloud environments

    • Extensive experience in IT security, with a focus on Security Operations, Access Management, and Policy Development

    • Strong knowledge of security frameworks, such as NIST and ISO27000 series

    • Up-to-date knowledge of emerging security threats, trends, and technologies

    • Expertise in network security protocols, cloud security solutions (Azure/AWS/GCP), firewalls, intrusion detection systems, VPNs

    • Proficient in vulnerability assessment tools, incident response frameworks, and risk management methodologies

    • Analytical mindset and problem-solving abilities to assess security risks and propose appropriate mitigation strategies

    • A basic understanding for compliance and risk management

Related Jobs

View all jobs

Cloud Security Engineer

Data Security Engineer

Cloud Security Engineer

Cloud Security Engineer

Cyber Security Engineer

Application Security Analyst

Get the latest insights and jobs direct. Sign up for our newsletter.

By subscribing you agree to our privacy policy and terms of service.

Industry Insights

Discover insightful articles, industry insights, expert tips, and curated resources.

Negotiating Your Cloud Job Offer: Equity, Bonuses & Perks Explained

How to Secure a Compensation Package That Reflects Your Value in the UK’s Booming Cloud Computing Sector Introduction Cloud computing has become the backbone of modern enterprise infrastructure. From small start-ups deploying microservices to multinational corporations scaling complex data analytics, the demand for cloud-savvy professionals continues to accelerate. If you’re working in cloud architecture, DevOps, infrastructure security, or any other mid‑senior role in the cloud domain, your expertise is in high demand—and so is your ability to negotiate a well-rounded compensation package. While an attractive base salary is essential, limiting your focus to that figure alone can mean missing out on substantial financial and lifestyle gains. Cloud-focused employers, including both tech giants (AWS, Microsoft Azure, Google Cloud) and smaller cloud-native consultancies, often layer their offers with equity, bonuses, and a host of perks to stand out in a competitive market. By delving deeper into these compensation components, you can maximise your earnings and ensure your new role supports both your career growth and personal well-being. In this comprehensive guide, we’ll explore every dimension of negotiating a cloud job offer. Whether you’re an established Cloud Solutions Architect eyeing a role at a cutting-edge start-up or a mid‑senior DevOps engineer seeking a leadership position at a global corporation, you’ll find insights on how to evaluate, compare, and negotiate all elements—from salary and equity to perks like flexible working and training budgets. Read on to discover how to turn a standard job offer into a holistic package that truly reflects your impact in the cloud computing arena.

Cloud Jobs in the Public Sector: Exploring Opportunities Across GDS, NHS, MOD, and More

Cloud computing has become a cornerstone of modern IT infrastructure, reshaping how organisations store data, run applications, and manage complex workloads. While the private sector has long embraced this shift, the UK public sector is now catching up at an accelerated pace. From the Government Digital Service (GDS) to the National Health Service (NHS), and even the Ministry of Defence (MOD), major public sector bodies are migrating critical systems to cloud platforms like AWS, Azure, and Google Cloud. For IT professionals and aspiring technologists, cloud jobs in the public sector offer a unique blend of technical challenge, job stability, and the opportunity to make a tangible impact on society. In this blog post, we’ll explore why cloud computing is so vital to government and healthcare, the types of roles available, the skills and qualifications you’ll need, and how to stand out in a competitive recruitment landscape.

Contract vs Permanent Cloud Jobs: Which Pays Better in 2025?

Cloud computing has become the cornerstone of modern business operations. From global enterprises migrating entire data centres to the cloud, to start‑ups building cloud‑native applications, the reliance on services such as Amazon Web Services (AWS), Microsoft Azure, Google Cloud Platform (GCP), and niche offerings (like IBM Cloud or Oracle Cloud) continues to rise sharply. As the adoption of cloud grows, so do the opportunities for professionals in the field—be it cloud architects, DevOps engineers, cloud security specialists, or site reliability engineers (SREs). Yet, in the midst of this burgeoning demand, cloud professionals face a critical question regarding their employment model: should they pursue day‑rate contracting, fixed-term contracts, or permanent positions? Each route offers a distinct mix of pay structure, job security, benefits, and career advancement possibilities. Making the right decision hinges on your personal priorities—whether that is maximising short‑term earning potential, achieving stable long‑term growth, or somewhere in between. This article breaks down the cloud job market in 2025, compares different forms of employment, and provides sample take‑home pay scenarios for three typical cloud roles. By exploring the pros and cons of each arrangement, you will be better equipped to decide which path aligns best with your career goals, financial needs, and lifestyle preferences.