CV Library brand banner

Security Engineer

CV LibraryFleet, United KingdomPosted 2h agohybrid
via Workable

At CV-Library, we have a simple vision: to help the world to work and we are looking for exceptional and talented people to help us realise this vision in both UK and overseas markets.

We are in a period of focused internal investment, following a year of key strategic acquisitions and significant investment across all parts of the business, from Tech and Data to People and HR, there’s never been a more exciting time to join us or a better place to grow your career!

The Role

Hours: Monday-Friday, 9:00-17:30
Location: Fleet
Working Pattern: Hybrid – 3 days a week on site

This is a security role built for someone who wants to own the threat, not just log it. As Security Engineer, you’ll be the person who understands what’s actually at risk across a modern Cloud native microservice platform and our internal IT estate, from SIEM alerts to Microsoft 365 endpoint security, and who sets the priorities that matter. You won’t be buried in compliance paperwork. You’ll direct a capable Platform Ops team on remediation while you stay focused on the threat picture, the tooling and the DevSecOps thinking that keeps CV-Library ahead of it.

You’ll report directly to the Platform & Service Operations Manager, with a genuine mandate to shape how security is done, not just document it. Compliance still matters, and you’ll keep ISO 27001 documentation and audit evidence in good shape as you go, but it’s the by-product of doing security well, not the job itself.

Responsibilities:

  • Own the day-to-day management of security alerts, investigations and incidents across CV-Library’s technology estate
  • Monitor emerging cyber threats and threat intelligence, assessing potential risks and recommending improvements to security controls
  • Lead the initial response to security incidents, coordinating containment and remediation activities with relevant technical teams
  • Maintain incident records, conduct post-incident reviews and ensure lessons are learned are embedded into processes, tooling and controls
  • Manage and continuously improve the organisation’s security tooling, including SIEM, endpoint protection, vulnerability management and cloud security solutions
  • Take ownership of endpoint and Microsoft 365 security, including device security, conditional access policies and identity protection controls
  • Define and maintain security standards and guardrails for cloud infrastructure and software delivery, working closely with Platform DevOps teams
  • Manage identity and access management processes, supporting user provisioning, access reviews and least-privilege principles
  • Act as the security subject matter expert, providing guidance on infrastructure, platform and application changes
  • Oversee the vulnerability management lifecycle, ensuring security weaknesses are identified, prioritised and remediated effectively
  • Coordinate external penetration testing activities and track remediation actions through to completion
  • Maintain security documentation, policies and audit evidence, supporting ongoing ISO 27001 compliance and certification requirements
  • Apply GDPR and data protection principles to ensure security controls, processes and documentation meet regulatory expectations
  • Support supplier and third-party security assessments, helping to identify and manage external risks
  • Assess the secure use of AI technologies across the business and champion a strong security culture by promoting best practice across best technology and non-technical teams

What we’re looking for

  • Strong technical knowledge of security tools, frameworks and best practice
  • Solid understanding of cloud-native infrastructure (AWS, Kubernetes/EKS) sufficient to assess and prioritise risk and to direct Platform Ops on remediation, without owning infrastructure changes directly
  • Experience with penetration testing engagement and vulnerability management processes
  • Understanding of endpoint protection technologies and policy configuration, including Microsoft 365 security tooling (e.g. Defender, Intune, Conditional Access)
  • Working knowledge of Identity and Access Management principles
  • Strong incident response and threat intelligence skills, including SIEM-based monitoring and triage
  • Familiarity with security accreditations such as ISO 27001 and what they require operationally
  • Working knowledge of UK GDPR and data protection principles, particularly as they relate to security control and audit documentation
  • Excellent communication skills, able to convey security matters clearly to both technical and non-technical audiences

We are actively committed to promoting a fully diverse and inclusive workforce and we welcome applications for this role from all candidates who meet the key requirements.

Please do not hesitate to get in touch should you require any reasonable adjustments to assist with your application.

Similar roles

  • Figma logo

    Manager, Mid-Market Sales (London, United Kingdom)

    Figma·London, United Kingdom

    Figma is growing our team of passionate creatives and builders on a mission to make design accessible to all. Figma’s platform helps teams bring ideas to life—whether you're brainstorming, creating a prototype, translating designs into code, or iterating with AI. From idea to product, Figma empowers teams to streamline workflows, move faster, and work together in real time from anywhere…

    • Full-time
  • Arbor Education logo

    Staff Engineer (Core Product)

    Arbor Education·United Kingdom

    Location: Remote About us At Arbor, we’re on a mission to transform the way schools work for the better. We believe in a future of work in schools where being challenged doesn’t mean being burnt out and overworked. Where data guides progress without overwhelming staff. And where everyone working in a school is reminded why they got into education every…

    • Remote
    • Full-time
  • Arbor Education logo

    Staff Engineer (Data)

    Arbor Education·United Kingdom

    Location: Remote About us At Arbor, we’re on a mission to transform the way schools work for the better. We believe in a future of work in schools where being challenged doesn’t mean being burnt out and overworked. Where data guides progress without overwhelming staff. And where everyone working in a school is reminded why they got into education every…

    • Remote
    • Full-time
  • HRM Homecare Services logo

    Support Worker Rutherglen

    HRM Homecare Services·Rutherglen, United Kingdom

    HRM Homecare Services is seeking compassionate and dedicated Support Workers to join our team in Rutherglen/Cambuslang. The Support Worker role involves providing essential care and support to individuals within their own homes, promoting independence, dignity, and quality of life. * Provide personal care and assistance with daily living activities such as bathing, dressing, eating, and medication support. * Support clients…

    • Contract
  • ITRS logo

    Interim FP&A Lead

    ITRS·London, United Kingdom

    ABOUT ITRS At ITRS, we make society's critical technology work. Our mission is to deliver automated and holistic IT observability solutions that safeguard critical applications and enable innovation. We are the only monitoring and observability platform designed for the most demanding and regulated industries — trusted by 90% of Tier 1 capital markets firms. We believe when our team thrives,…

    • Hybrid
    • Contract
  • Wifinity logo

    Customer Service Advisor

    Wifinity·United Kingdom

    This role offers you: Remote-based working / a salary of £26,436 per annum / additional performance related pay / 25 days holiday / private medical cover / pension / gym membership contributions / the chance to learn from and work with some highly skilled CS professionals. This role entails: * 40 hour a week shift patterns that will include 5…

    • Remote
    • Full-time
  • Atariinc logo

    Senior Offensive Security Engineer

    Atariinc·Newcastle upon Tyne, United Kingdom

    <h3><strong>About Atari</strong></h3> <p>Atari is an interactive entertainment company and an iconic gaming industry brand recognized worldwide for its multi-platform games and licensed products. Atari owns and/or manages a portfolio of more than 400 games and franchises, including globally recognized brands such as <em>Asteroids®</em>, <em>Centipede®</em>, <em>Missile Command®</em>, <em>Pong®</em>, and <em>RollerCoaster Tycoon®</em>.</p> <p>The Atari family of brands includes Digital Eclipse, Nightdive Studios,…

    • On-site
    • Full-time
  • Rand Europe logo

    Senior Research Analyst - Emerging Biotechnology

    Rand Europe·Cambridge, United Kingdom

    RAND Europe is an independent, not-for-profit research organisation whose mission is to help improve policy and decision-making through rigorous and independent research and analysis. We benefit the public interest through the impact and wide dissemination of over 200 projects per year. Our work at its most impactful changes policy, practice and process to the benefit of the public good. That…

    • Hybrid
    • Full-time