
Lead Security Engineer
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United Kingdom.
• Oversee security engineering and testing initiatives across Kainos Platforms and Services.
• Establish the framework for security testing methodologies, engagement scopes, deliverables, and selection of tools/technologies.
• Mentor and develop junior security engineers.
• Collaborate with agile delivery teams to integrate robust security practices throughout the software development lifecycle.
• Disseminate knowledge and educate both customers and Kainos team members on security practices.
• Manage, coach, and nurture staff with an emphasis on performance and career advancement.
• Provide leadership and direction to the team while addressing complex security challenges.
• Convert external penetration testing results into actionable tasks.
• In-depth knowledge of securing web applications and cloud platforms such as AWS and Azure.
• Proven experience in the defense sector.
• Possession of current, active security clearance.
• Proficient in testing software and infrastructure security using both manual and automated tools.
• Capability to execute and document penetration tests on web applications, networks, and computer systems.
• Expertise in evaluating software and infrastructure source code from a security standpoint.
• Proficient in Continuous Security, Continuous Integration, and Continuous Delivery methodologies.
• Familiarity with security standards and regulations, including NCSC, NIST, CIS, PCI, GDPR, OWASP ASVS, HIPAA, and SOC2.
• Understanding of cyber security attack vectors, including OWASP Top 10, SQL injection, XSS, XXE, and MITM.
• Ability to communicate threats and risks through threat modeling exercises and workshops.
• Strong communication skills to convey security complexities to audiences with varying levels of technical expertise.
• Proven track record of managing, mentoring, and coaching team members.
• Proficient in programming or scripting across Windows, Linux, and macOS platforms.
• Keeps current with emerging threats and attack methodologies.
• Desirable: penetration testing certifications such as OSCP, CREST, TIGER, or equivalent.
• Desirable: experience collaborating with external penetration testing firms.
• Desirable: familiarity with tools such as Burp Suite, OWASP ZAP, Nmap, Nessus, Kali, and Metasploit.
• Desirable: understanding of OSINT, network scanning, enumeration, sniffing, session hijacking, social engineering, firewalls, honeypots, IDS/IPS/WAF/AV/DLP, cryptography/PKI, IoT threats, malware, and ransomware.
• Desirable: active engagement in knowledge-sharing activities and the security community.
• Desirable: experience in an Agile work environment.
• People-first culture.
• Support for growth and career development.
• Commitment to diversity, equity, and inclusion.
• Recruitment accommodations and adjustments.
• Benefits provided by Kainos (specifics not detailed).
OCHIN, Inc.
Dynanet Corporation
Solutions for Information Design, Inc.
Fuze Health
Get handpicked remote jobs straight to your inbox weekly.