Online since 1999 | 5,881 IT Jobs Live NOW

Senior Cyber Specialist - Penetration Testing

Premium Job From Royal London - AMS
Recruiter: Royal London - AMS
Listed on: 22nd July
Location: Edinburgh
Salary Notes: Competitive
Type: Permanent
Start Date: 2020-07-22

Founded in 1861, we're the UK's largest mutual life, pensions and investment company. Our award-winning customer service and our mutuality means we can give customers that little bit more, and you can trust us to be there for you when it counts.

Senior Cyber Specialist - Penetration Testing


Permanent Contract

Closing date - 31/07/20

At Royal London we want to attract the best talent to help us achieve our vision of becoming the most trusted and recommended financial company in the UK. We are the largest mutual life, pensions and Investment Company in the UK. 

For more than 150 years, people have been at the heart of all that is great about Royal London. We know that this is a difficult and uncertain time for everyone and are doing everything we can to support our customers, our people and candidates.

Maintaining the Spirit of Royal London is of paramount importance to us as we face new and different ways of working. That is why we are embracing technology throughout our recruitment process to support interactions. As you embark on your journey with us will engage with you via email, telephone and video to ensure we all remain safe. We are committed to wellbeing and at this challenging time, it remains our priority. 

We are currently looking to recruit a Senior Cyber Specialist - Penetration Testing to join our Group Technology & Change team on a permanent basis in our Edinburgh or Wilmslow Office.

The role will assure the response to a cybersecurity event or incident, taking the lead to contain the threat to the Royal London business and support the remediation activities to stabilise service. Additionally, the role will be responsible for cyber-attack countermeasures and techniques with a focus on security testing to ensure risk mitigation controls deployed to prevent cyber events are working effectively.  

Key Accountabilities

  • Minimise and control the damage resulting from cybersecurity incidents
  • Ensuring that the appropriate incident management and response controls are in place
  • Operating as required in order to enable the identification, protection, detection, response and recovery of RLG information assets.

Skills and Experience

  • Experience managing security events are investigated and tracked to remediation within agreed SLA's
  • Support the process, procedure, tools, measures and metrics to ensure identification and remediation of operational deficiencies
  • Experience substitute for the Head of Department where necessary, communicating the RLG threat level to senior management, translating technical security risks into business problems
  • Experience of threat intelligence searching, using both trusted commercial sources and open source intelligence information of threat activity
  • Management of escalation for emerging cyber threats demanding swift action
  • Operate threat intelligence tooling, keeping configurations current to detect emerging threats
  • Proactive threat analysis of information received to identify potential threats to RLG, and disseminate the results of the analysis to prevent those threats from materialising
  • MI reporting of the effectiveness of RLG security controls, assuring they are operating within the expected guidelines and risk decisions are threat driven.
  • Maintain a threat dashboard for communicating the threat level within RLG
  • Incident management, providing security resources with threat intelligence to support the remediation activity.

Essential Criteria

  • Ability to mentor and support a team of Cyber Security professionals
  • Demonstrable hands-on experience and accreditation in the fields of incident response countermeasures, security penetration testing.
  • Pentesting experience and familiarity with Pentesting tools e.g. KALI Digital forensic investigations experience an advantage
  • Technical security qualifications e.g. CISSP, SSCP, GIAC - GEVA, OSCP, CEH or equivalent
  • Knowledge of perimeter and host security intrusion techniques, including threat hunting for evidence of this activity
  • Knowledge and hands-on experience of security information and event management (SIEM) tools from industry leaders
  • Familiar with IPS, WAF, DLP, Identity & Data Management and Network Security technologies
  • Familiar with vulnerability management and application security technologies
  • Familiar with audit event collection and reporting toolsets

Desirable Criteria

  • Previous experience of working within a regulated environment, ideally within the financial services industry
  • OSCP qualification is highly advantageous
  • Experience working within a Pentesting company previously is highly advantageous
  • Digital forensic investigations experience is advantageous
  • Experience of working with external threat intelligence bodies such as NCSC

What we offer

  • We've always been proud to reward employees by offering a number of benefits such as Pensions and Protection, Performance and role-related benefits, Lifestyle and Wellbeing 
  • Our People Promise is something we live up to every day. We know we can rely on you, and you can expect plenty from us in return.
  • Glassdoor have again ranked as among the best places to work in the UK 

Our culture is welcoming, friendly, flexible and we aim to make you always feel included. We are an equal opportunities employer which means we believe in embracing difference as it makes us collectively stronger. Our diverse people bring us different skills - whatever their educational background, disability, gender, age, sexual orientation, race, religion or belief.

We also welcome applications from individuals who have taken an extended career break or those who are transitioning from different sectors. To support this we are always open to discussing flexible working to give you the freedom to be your best. It's what makes Royal London a great place to work.

The first pillar of our People Promise is designed to make sure you 'work somewhere inclusive'. We want to live up to this promise; it's good for our people and good for our customers too, because our workforce should reflect our communities.

Contact Name: Group Royal London
Reference: TJ/8778/2272-33455806
Job ID: 2841284

Browse all skill types