PRINCIPAL SECURITY ENGINEER UP TO £900 Day Rate (Outside IR35) - 6 Month Renewable (2 Year Projected Contract) Hybrid Working SECURE has Strategically Partnered with a leading consultancy to support a Global FinTech Leader operating under strict Regulatory Frameworks They are looking for an experienced Principal Security Engineer to provide Credible, Hands-On Technical Leadership to a Team of Engineers for the Design, Engineering, Implementation of their Network & Infrastructure Security Capabilities with Architecture, Automation, Operational Ownership & Stakeholder Engagement. Their current Strategic Technologies include Imperva WAF & DDoS, ExtraHop NDR & Illumio Micro-Segmentation. Experience across these technologies is highly desirable, although they'll value genuine Hands-On Depth & Successful Operational Ownership more highly than "Superficial Familiarity" with every Product.
Key Responsibilities of Principal Security Engineering role would include:
- Security Engineering Leadership across Network & Infrastructure
- Translate Security Architecture, Risk & Control Requirements into Practical, Scalable Engineering Solutions
- Lead Complex Security Engineering Initiatives & Technical Oversight & Assurance from Initial Requirements & Architecture through Design, Testing, Implementation & Transition into Operational Service.
- Imperva Web Application Firewall - Lead Engineering, Implementation & Development of the Imperva WAF Estate
- Define WAF Architecture, Configuration Standards, Security Policies & Deployment Patterns.
- Establish Controlled Processes for Policy Changes, Exceptions, Testing & Approvals
- Investigate WAF Alerts & Blocked Traffic to Identify Attacks, Configuration Issues & Opportunities for Improved Detection.
- Lead Consolidation of DDoS Protection Capability onto Imperva, Reducing Overlapping Technologies & Unnecessary Operational Complexity.
- Define Target Architecture & Migration Approach for DDoS Protection.
- Establish Appropriate Controls for Both Volumetric & Application-Layer DDoS Attacks
- Own Engineering & Operational Maturity of ExtraHop Network Detection & Response Capability
- Lead Design & Implementation of Illumio Micro-Segmentation Capability
- Develop Workload Labelling, Application Dependency Mapping & Segmentation Models
- Security Automation & Security-as-Code - core expectation of the role is to move Security Engineering away from Repetitive Manual Administration towards Automated, Repeatable & Auditable Engineering Practices
- Lead Adoption of Automation-First Approaches across Security Engineering
- Use Vendor APIs, Scripting & Infrastructure-as-Code Techniques to Automate Deployment & Configuration.
Key Skills & Experience Required:
- Technical Leadership & Direction through Expertise, Credibility & Influence
- Consultative, Engagement-Led Stakeholder Engagement, Building Credibility Quickly with Software, Infrastructure, Network & Security Engineers.
- Hands-On Experience with either Imperva, ExtraHop and/or Illumio is Highly Desirable.
- Essential Technical Experience will include Web Application Firewalls & Application Security Controls; DDoS Protection & Mitigation; Network Detection & Response; Network & Workload Micro-Segmentation; Network Security Architecture; Enterprise Networking & TCP/IP; Security Monitoring & Telemetry; Infrastructure & Security Automation; APIs & Scripting; Infrastructure as Code; Cloud & Hybrid Infrastructure Security; Security Incident Investigation & Response
- Networking Knowledge: TCP/IP; DNS; Routing; Firewalls & ACLs; Load Balancing & Reverse Proxies; Network Segmentation; East-West & North-South Traffic; Application Communication Flows; Cloud Networking; Network Telemetry & Packet-Level Investigation.
- Automation & Engineering Skills across Python, PowerShell (or comparable Scripting Languages); REST APIs; JSON / YAML; Git (or comparable Source-Control Platforms; Infrastructure-as-Code (Terraform or equivalent); CI/CD Tooling; Automated Configuration Management; Configuration Testing & Validation; Security Orchestration & Workflow Automation.
- You Do Not Need to be Full-Time Software Developer, but you should approach Security Technology as an Engineering Problem rather than a Collection of Manually Administered Appliances
Desirable Experience:
- Experience Operating within Financial Services or another Regulated Industry.
- Experience Engineering Security Controls across Large or Complex Enterprise Environments
- Experience of Hybrid Cloud & On-Premises Infrastructure
- AWS, Azure or other Major Cloud Platform Security Experience
- Experience Integrating Security Tooling with SIEM, SOAR, ITSM & Observability Platforms.
- Experience Designing or Implementing Zero Trust Architectures.
- Experience with Identity-Aware Segmentation & Workload Protection.
The Measure of Success will therefore be both Technical & Organisational:
Stronger Controls, Greater Automation & Reduced Exposure, combined with an Engineering Community that sees Security Engineering as a "Trusted Partner" rather than a "Barrier to Delivery".
Searches:
- Principal Security Engineer
- Lead Security Engineer
- Cloud Platform Security Engineer
- IAM
- Terraform
- Application Security Engineer
- Threat Detection
- Security Architect
- Security Solutions Architect
- SecOps Engineer
- Network Engineer
- SecOps