Key Details
Position: Cyber Security Engineer
Security Clearance: DV (Developed Vetting)
Location: Huntingdon, UK (On-site 4/5 days a week)
Responsibilities
* Develop creative solutions to complex technical issues and problems
* Work with engineering teams to maintain required security posture against baseline requirements
* Coordinate with the Security Monitoring engineering team to forward logs to the SIEM capability
* Collaborate with customers and agencies to develop new policies, design processes, and procedures, and create technical designs
* Assess system vulnerabilities, implement risk‑mitigation strategies, validate secure systems, and test security products and systems to detect weaknesses
* Maintain and support security‑enforcing functions
Core Skills
* Experience working in MOD or Home Office project environments
* Strong knowledge of network and system security, including firewalls, IDS/IPS, micro‑segmentation, and host security
* Hands‑on experience with security products Trellix, Ivanti, ClearSwift, Yubikey
* Understanding of secure coding practices and common vulnerabilities (OWASP Top 10, SANS Top 25)
* Expertise in identity and access management (IAM), including RBAC, ABAC, JWT and cookie‑based authentication
* Incident detection and response in MOD environments
* Security compliance and regulatory frameworks (e.g., NIST, CIS Benchmarks)
* Experience working with Kubernetes at an administrative level
Soft Skills
* Strong leadership and mentoring abilities
* Effective communication with development, operations, and security teams
* Ability to advocate for security best practices in a DevOps culture
Desirable Skills
* Expertise in Kubernetes security (RBAC, network policies, pod security standards, secrets management)
* Knowledge of container runtime security (container escapes, rootless containers, sandboxing)
* Image security best practices, including scanning, signing, and provenance verification
* Secure deployment patterns using Tanzu and Kubernetes
* Runtime security monitoring
* Secure CI/CD pipeline design with security testing using tools such as Git, SonarQube, and GitHub Actions
* Implementation of Infrastructure as Code (IaC) security (Terraform, Ansible)
* Secrets management in CI/CD pipelines using Vault or Kubernetes Secrets
* Security automation and policy enforcement using GitLab CI and Jenkins
* Proficient in Python and PowerShell for security automation
* API security knowledge (OAuth, JWT, API gateways, rate limiting)
* Experience with Security as Code for automated policy enforcement
* Strong knowledge of cloud security principles in a containerised environment
* Kubernetes security posture management using tools like Trivy
* Secure ingress/egress controls and service mesh security (Istio)
* Encryption strategies for data at rest, in transit, and in use
* Network security best practices for Tanzu container networking (NSX, Rancher)
* Compliance monitoring and security auditing for cloud‑native environments
Benefits
* Contributory Pension Scheme
* Private Medical Insurance
* 33 days Annual Leave (including public and privilege holidays)
* Flexible benefits (life assurance, health schemes, gym memberships, annual buy‑and‑sell holidays, cycle to work scheme)
* Flexi‑Time
Pay Range
£47,600.00 - £61,000.00
Commitment to Non‑Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.
#J-18808-Ljbffr