Cybersecurity Engineer (Public Sector)
- 1-year contract, renewable
- Hybrid work arrangement
- Government project
About the Role
This role applies foundational security principles to real-world engineering challenges, executing security tasks with growing independence. Depending on area of focus, responsibilities may span improving security implementations, automating security processes, reviewing secure code and design patterns, and evaluating new cybersecurity tools. You'll work closely with security and product teams to support threat modelling, implement security controls, and secure government systems.
Key Responsibilities
Cybersecurity Operations
- Perform routine reporting and dashboarding, using automation to improve efficiency
- Support review of VAPT findings and contribute to remediation planning
- Validate security vulnerabilities and findings from assessment reports
- Refine incident response playbooks
- Contribute to compliance documentation and evidence collection
- Assist with implementing security controls and operational security tasks
- Participate in threat modelling and identify security requirements from policy
- Perform periodic IAM role reviews to uphold least-privilege access
Security Architecture & Engineering
- Apply security standards and controls across CI/CD pipelines, Kubernetes platforms, and cloud environments
Cyber Defence & Incident Response
- Support incident response activities, escalating complex issues appropriately
- Perform alert triage and assist investigations across security monitoring platforms
- Contribute to refining detection rules, playbooks, and response runbooks
- Support guided threat hunting to identify potential indicators of compromise
Product Engineering
- Deliver POCs or features spanning multiple components, balancing security, performance, and maintainability
- Use code and cloud security analysis tools, remediating findings appropriately
- Recommend improvements to product security, performance, and team efficiency
Emerging Technology Research
- Test new tools in lab environments and summarise findings
- Contribute to POC initiatives with defined objectives and outcomes
Collaboration & Growth
- Collaborate with peers and stakeholders to execute tasks effectively
- Share knowledge, resources, and lessons learnt openly
- Suggest improvements to enhance team effectiveness
What We're Looking For
Technical Skills
- Foundational knowledge of security architecture, secure system design, and threat modelling
- Ability to perform guided vulnerability validation and support remediation
- Familiarity with securing CI/CD platforms, Kubernetes environments, and cross-cutting platform products
- Exposure to developer-centric tools, including agentic AI workflows and coding assistants
- Familiarity with SIEM platforms, EDR tools, and cloud-native security monitoring
- Ability to follow and contribute to detection logic, incident response playbooks, and threat hunting processes
- Scripting/automation skills (e.g. Python, Bash) for security tooling and workflow automation
- Understanding of IAM, secrets management, and zero trust principles
Behavioural Fit
- Works independently with minimal supervision
- Proactively identifies and addresses issues, knowing when to escalate
- Adapts effectively to changing priorities
- Collaborates constructively with peers and stakeholders
- Contributes positively through knowledge sharing and openness
Education & Experience
- Degree in Infocomm Security, Computer Science, Computer/Electronics Engineering, or Information Technology
- Minimum 2 years of relevant experience, or demonstrated potential backed by a strong track record
Certifications (Desirable)
- OSCP, CISSP, or other relevant cybersecurity certifications
/Ref: T24-238