Job description
We are looking for an experienced Information Security Engineer to join our rapidly expanding team in Edinburgh.
Enoda is establishing an information security capability to respond to increasing cyber security threats, make consistent risk-based decisions, and integrate security capabilities with the business.
We are seeking a candidate who is pragmatic, passionate about cyber security, able to work collaboratively with teams, and driven to learn and succeed.
The role involves designing, building, and operating security controls and procedures for both the organization and its products. This is a hands-on engineering position with the opportunity to lead and develop the future of cyber security within the company, providing technical support for confident and swift decision-making.
Who we are
Energy is the primary input to everything. Our continued prosperity is dependent on reliable, affordable, clean electricity.
Enoda is an innovator in energy platforms, developing advanced technologies for grid operators and developers that remove constraints to decarbonisation.
Integrated hardware and software solutions slot into existing infrastructure, enabling the grid to become self-balancing and the primary provider of system stability.
We are a mission-driven organisation committed to enabling humanity to prosper on 100% renewable energy. We are averse to introducing bureaucracy and are building a working culture that enables us to achieve our purpose and change the world.
As an Information Security Engineer at Enoda, you'll spend your time
- Establishing, leading and developing the information & Cyber Security function
- Working daily with engineering teams to improve the delivery process, ensuring that test/development is security-focused right from the beginning
- Being accountable for implementing and operating the security processes and tools in our platforms
- Improving our general security posture across on-premises and remote systems including applications and networks
- Configuring Windows and Linux host-based security as well as network and cloud-based security systems
- Improving our monitoring and alerting systems with a focus on enhancements with specific and relevant security data points
- Providing expertise on application, data and network security to our wider engineering teams – engaging with them to ensure consistent adoption of security policies and best practice
- Defining, implementing and leading the Security Incident Response process/policy with regular improvements, testing and adherence
- In addition, you will contribute to the creation and ongoing maintenance of security engineering principles (secure by design and privacy by design), patterns and standards to reflect best practices and effective use within the company
The key experience we're looking for
- Experience in information security, network and/or application security engineering, or another closely related discipline
- Solid understanding of Secure by Design and Privacy by Design principles
- Experience working with ISMS such as ISO27001 and cyber essentials
- Experience in IT Infrastructure roles (covering Azure Active Directory and Office 365)
- Good knowledge of most VPN, MFA, Azure Conditional access, SSO, TLS, and SIEM
- Experience with public and private cloud security frameworks, standards, and procedures including identity and access federation is desired
- Experience defining and operating a Security Incident Response process
- Demonstrated experience with cyber security project management, requirements analysis and mapping, testing, implementation, and optimization
- Have a strong comprehension of emerging threats, offensive/defensive technologies, and countermeasures
The following skills are advantageous
- Experience in exposure to offensive or defensive penetration testing
- Specific expertise in threat assessment, attack surface management, data security, the network stack, DNS, VPC security, internet gateway, web app firewall (WAF), API Gateways
- Experience working with Defender 365, Purview and Azure conditional access
- Experience working with Google Cloud Platform
What we offer
- Salary: £65,000- £75,000 dependent on skills & experience
- A flexible pension policy tailored to your requirements
- A balanced workday that allows you time to enjoy some outside thinking space
Enoda is cultivating a culture where we embrace our vision of sustainable prosperity for everyone. Built on the principles of win-win outcomes and extreme ownership, we strive to act with integrity and be accountable.
Teams are encouraged to be relentless in the pursuit of scientific truth; we strive on the challenge of solving the most complex problems together.
Equal opportunity statement
We are a values-led business and alignment with, and defending our values is critical to successful long-term relationships with colleagues, commercial partners and customers.
As an equal-opportunity employer, we're committed to creating an environment which engenders equality, diversity and inclusion. We actively encourage applicants from all protected characteristics and commit to providing any reasonable adjustments required during the application and assessment stages and upon joining Enoda.
If you have questions regarding our recruitment process, please get in touch with our Head of Talent Acquisition at: [email protected]
We look forward to your application!
https://enodatech.com