Cyber Security Engineer
Tiger Resourcing Group
Cybersecurity Engineer
Job Summary
Supports the handover of existing security tools, including oversight and management of access control, technical management of security materials such as cryptographic keys, passwords and certificates, as well as additional security monitoring, vulnerability management, tool maintenance and configuration.
The role will also provide knowledge transfer and training to the successor operator’s security architecture staff.
Essential Job Duties and Responsibilities
Ensure RCC Handover project objectives are supported by appropriate cybersecurity requirements.
Define, document and perform technical changes in security tooling to support RCC Handover.
Lead cybersecurity assurance within RCC Handover change boards and design gateways.
Ensure appropriate security support processes are followed by the RCC Handover team.
Ensure the customer and successor operator understand the technical impact of RCC Handover tasks.
Provide input into other cybersecurity, contingency planning and related RCC Handback activities.
Create and update technical documentation for security tools, processes and information assets as directed by the RCC Handover leadership team.
Assess RCC Handover change control requests for potential impact on existing security mechanisms and ensure any potential compromise or weakening of security controls is minimised.
Perform security monitoring and vulnerability management of information assets in scope of RCC Handover tasks, supporting existing business-as-usual teams.
Perform handover of security secret materials, including cryptographic keys and certificates, devices and access control credentials to the customer and/or successor operator.
Provide reporting to the RCC Handback leadership team.
May be required to work across customer, TfL, successor operator sites and data centres.
Minimum Job Requirements
Qualifications
Essential
Certification as an Information Security professional, for example:
IISP
CISA
CISM
CISSP
CCSP
ISA
Desirable
University degree in a numerate subject such as Computer Science, Mathematics, Engineering or Natural Sciences.
Information privacy/data protection certifications such as CIPP/E and CIPM.
HMG IA qualifications / CLAS.
CREST-registered penetration tester and/or security architect.
ITIL v3, PRINCE2 Foundation and/or TOGAF.
Security, IT infrastructure or networking vendor certifications.
Skills, Experience and Knowledge
Essential
Strong experience taking a leading role in the establishment and implementation of security architecture, policies and procedures.
Good understanding of enterprise-scale security management processes and infrastructure.
Experience working with current IT security standards and regulations such as PCI-DSS, ISO 27001 and UK data protection legislation.
In-depth understanding of information security control tools, for example:
Splunk Cloud
CrowdStrike
Qualys
Trellix
Tripwire
Cisco IPS
F5
Centrify
Experience working with enterprise IT infrastructure and technologies such as Microsoft Windows Server, Cisco and Linux.
Desirable
Experience within transactional revenue, embedded systems, smartcards and mobile payment systems.
Knowledge or experience of security architecture across major public cloud services such as:
Microsoft Azure
Amazon Web Services
Google Cloud
Cloud Access Security Brokers
Knowledge of cryptographic services, products and HSM devices.
Knowledge of wider security, audit, risk and compliance standards including:
PCI-P2PE
PCI-POI-PTS
ISO 27701
ISO 27005
ISO 31000
NIST
GDPR
Governance, Risk and Compliance tools
Experience with quality management systems and external audit standards such as ISO 9001.
Application opens at the source listing. Free for jobseekers.