Cybersecurity Engineer (Monitoring and Response)
Summary
Cybersecurity Engineer designs, integrates, and validates security controls for government/defence clients, ensuring compliance with standards like ISO 27001 and NIST while managing risk assessments and SIEM deployments.
ROLES & RESPONSIBILITIES:
Deliver assigned work packages, ensuring scope, schedule, budget, quality, configuration, and acceptance requirements are met.
Develop and maintain detailed delivery plans, including milestones, resource planning, delivery gates, acceptance criteria, and deliverables.
Lead and coordinate multidisciplinary teams and third-party suppliers to achieve programme objectives and manage interfaces.
Translate programme and contract requirements into actionable technical and delivery tasks with traceability to acceptance criteria.
Oversee the integration of cybersecurity components within the overall system architecture and resolve technical interface issues.
Plan and manage verification, validation, and qualification activities, including integration testing, system validation, penetration testing, and vulnerability management, ensuring evidence is available for customer acceptance.
Manage secure deployment, cutover, and operational transition, including deployment plans, runbooks, training, operational handover, and customer acceptance.
Identify, assess, and manage project risks, issues, and opportunities, implementing mitigation measures and escalating where necessary.
Maintain configuration management of technical deliverables, documentation, standard operating procedures, and maintenance materials.
Serve as the primary customer interface for delivery-related matters, managing expectations and contractual commitments.
Ensure compliance with applicable cybersecurity standards, regulations, and programme requirements (e.g. ISO 27001, IEC 62443, IM8, CCoP, NIST).
Drive continuous improvement in delivery processes, cybersecurity practices, and operational resilience.
Support proposals, commercial discussions, and scope changes as required.
WORK EXPERIENCE REQUIREMENTS:
Minimum 5–7 years of experience in cybersecurity engineering or a related technical role.
Subject Matter Expert (SME) in one or more cybersecurity domains, products, or vendor technologies.
Experience delivering cybersecurity solutions for Government, Defence, or Critical Information Infrastructure (CII) customers.
Experience conducting cybersecurity risk assessments and risk management activities.
Experience administering and troubleshooting Windows and/or Linux operating systems.
Working knowledge of:
Cybersecurity concepts, technologies, and terminology.
Computer networking concepts and protocols, including TCP/IP, network segmentation, firewalls, and IDS/IPS.
Cybersecurity standards, regulations, and frameworks (e.g. ISO 27001, IM8, CCoP, IEC 62443, NIST CSF).
Verification, validation, and qualification (VV&Q) processes.
IT Service Management (ITSM) and configuration management.
Secure Software Development Lifecycle (SSDLC) principles.
Experience with personal projects or homelabs (cybersecurity or non-cybersecurity) is an advantage.
QUALIFICATIONS, CERTIFICATIONS & EDUCATION
Mandatory (One or more of the following)
Degree in Information Security (preferred), Information Technology, or Computer Science.
Certified Information Systems Security Professional (CISSP).
Certified Information Security Manager (CISM).
CompTIA Security+.
Project management certification (PMP, PRINCE2, or APM).
Preferred
Information Systems Security Architecture Professional (CISSP-ISSAP).
Information Systems Security Engineering Professional (CISSP-ISSEP).
Technical Skills
Strong understanding of cybersecurity principles, frameworks, and industry best practices.
Experience with one or more of the following:
Identity and Access Management (IAM), Privileged Access Management (PAM), Privileged Identity Management (PIM), and Multi-Factor Authentication (MFA).
Network security, network monitoring, and intrusion detection/prevention systems (IDS/IPS).
Public Key Infrastructure (PKI), Certificate Authority (CA) operations, and digital certificate management.
SIEM/SOAR deployment, integration, and use-case development.
Knowledge of backup, recovery, and business continuity processes.
Hands-on experience deploying and customizing Commercial Off-The-Shelf (COTS) cybersecurity products.
Understanding of Software Development Life Cycle (SDLC) and secure software development practices.
Experience integrating and troubleshooting complex systems.
Ability to develop and execute system test plans and validation activities.
Project & Delivery Skills
Ability to translate customer requirements into practical cybersecurity solution designs.
Experience supporting testing, evaluation, and coordination across multiple technical teams.
Experience managing project risks, opportunities, and subcontractor deliverables.
Strong technical documentation and procedural writing skills.
Ability to develop implementation guides, training materials, and deployment support documentation.
Familiarity with service delivery processes and quality assurance practices.
Strong communication skills to engage engineering teams, project managers, and customers.