CrawlJobs Logo

Senior Security Engineer

pexa.co.uk Logo

PEXA UK

Location Icon

Location:
United Kingdom, Leeds

Category Icon
Category:
IT - Administration

Job Type Icon

Contract Type:
Not provided

Salary Icon

Salary:

65000.00 - 75000.00 GBP / Year

Job Description:

The Senior Security Engineer will provide hands-on technical leadership within the UK, ensuring that cyber security strategy and architecture defined by AU are implemented effectively across UK subsidiaries, aligned with local jurisdictional compliance requirements. This role bridges between AU Security, outsourced partners, and UK subsidiaries (Optima, Smoove, Legal Eye, Amity Law), ensuring successful delivery of projects, uplift initiatives, and BAU operational excellence. This position will own UK technical approvals, impact assessments, and project-specific security delivery, acting as the local escalation point for incidents and implementations.

Job Responsibility:

  • Maintenance and Operational Security: Ensure all security solutions remain operationally effective
  • Ensure technical teams timely patch applications, systems, software, and hardware
  • Maintain and audit secure configurations for devices, applications, and cloud environments
  • Access Control and Identity Management: Conduct regular user and privileged account reviews
  • Manage and monitor Privileged Identity Management (PIM) profiles and elevated access accounts
  • Coordinate with IT and HR for onboarding/offboarding
  • Tool, Infrastructure, and Encryption Management: Maintain and optimise security infrastructure and tools
  • Oversee encryption key and certificate management
  • Work with vendors and internal teams to ensure tools remain current
  • VPN, Network & Firewall Security: Design, configure, and maintain secure VPN and Zero-Trust network solutions
  • Manage access controls, MFA policies, and authentication mechanisms
  • Administer and maintain network firewalls
  • Collaborate with the SOC to investigate network-related incidents
  • Document network topology, firewall rules, and VPN configurations
  • Endpoint Security: Deploy, manage, and monitor Endpoint Detection & Response (EDR) and associated endpoint controls
  • Maintain secure endpoint baselines
  • Integrate endpoint compliance and posture assessments with MDM platforms
  • Work with the SOC on endpoint incident investigations
  • DevSecOps & Application Security: Provide hands-on security guidance to development teams
  • Embed security into CI/CD pipelines
  • Contribute to secure cloud architecture and application design
  • Support application security testing, sign-offs, and remediation of vulnerabilities
  • Monitoring, Threat Management & Incident Response: Collaborate with the SOC team to monitor, investigate, and triage security alerts and incidents
  • Conduct log and event analysis
  • Participate in incident response, root cause analysis, and post-incident reviews
  • Governance, Compliance & Continuous Improvement: Maintain accurate documentation
  • Support compliance efforts against frameworks such as ISO 27001, SOC 2, CIS benchmarks, and Cyber Essentials Plus
  • Participate in change management, risk assessments, and architecture reviews
  • Identify process optimisation opportunities
  • Awareness & Training: Assist with internal security awareness initiatives
  • Promote a culture of security accountability
  • Partner & Vendor Engagement: Serve as the primary UK liaison with third-party security partners
  • Ensure outsourcing arrangements deliver effective outcomes
  • Collaborate with AU procurement and security leadership on vendor performance
  • Security Advisory & Collaboration: Provide security consultancy and expertise to IT, DevOps, and Infrastructure teams
  • Contribute to vulnerability management and remediation planning
  • Evaluate emerging tools, frameworks, and security technologies
  • Support penetration testing, application reviews, and other proactive security improvement initiatives

Requirements:

  • Proactive, can-do attitude to get things done quickly and efficiently
  • Strong collaboration and communication skills
  • Willingness to contribute ideas to the security programme
  • Demonstratable first-hand experience in achieving organisational adherence to security best practices
  • Experience in the practical protection of a remote working laptop estate and SaaS cloud solutions
  • Experience in identity and access management solutions
  • Experience in device business automation and updates
  • Experience in the security aspects of cloud web application hosting and defence measures like WAF

Nice to have:

  • Technology product specific desirable skills: Palo Alto Cortex ERD
  • Palo Alto Global Protect VPN
  • Palo Alto Prisma Cloud Firewall
  • Nucleus vulnerability management
  • Airlocker application whitelisting
  • Trend Micro and Abnormal email security
  • OKTA / Entra IDAM
What we offer:
  • Your growth: We encourage you to hit your personal and professional learning and development goals with our tailored programs and tools
  • Your wellness: We care about your holistic wellbeing
  • Your work/life blend: We want to help you create your ideal work/life blend

Additional Information:

Job Posted:
December 11, 2025

Employment Type:
Fulltime
Work Type:
Hybrid work
Job Link Share:
Welcome to CrawlJobs.com
Your Global Job Discovery Platform
At CrawlJobs.com, we simplify finding your next career opportunity by bringing job listings directly to you from all corners of the web. Using cutting-edge AI and web-crawling technologies, we gather and curate job offers from various sources across the globe, ensuring you have access to the most up-to-date job listings in one place.