Security Engineer

Security Engineer

Posted 2 weeks ago by DVF Recruitment

£90,000 Per year
Fixed-Term
Hybrid
Greater London, England, United Kingdom

Summary: The Security Engineer role at a top-tier law firm in London involves delivering strategic security initiatives within a well-established InfoSec function. The position requires a solid technical background in security operations, focusing on hands-on engineering and contributing to security improvements. The role is a 12-month fixed-term contract, emphasizing collaboration with IT and Development teams to enhance the firm's security posture. Candidates should have experience in regulated environments, particularly in legal or financial services sectors.

Key Responsibilities:

  • Supporting the InfoSec team to drive continuous improvement across security operations.
  • Delivering secure designs and implementations for key security maturity projects.
  • Integrating new security technologies and automating routine security processes.
  • Working closely with IT and Development teams to embed security-by-design principles.
  • Running vulnerability scans, patching, and managing threat responses.
  • Managing security tooling – from DLP and SIEM to EDR, IAM, and more.
  • Supporting incident, change, and problem management workflows.
  • Documenting technical designs and representing InfoSec in key governance forums.

Key Skills:

  • Proven experience in a Security Engineer role within a legal, financial services, or similarly regulated environment.
  • Strong technical expertise across network, cloud, and endpoint security.
  • Hands-on experience with tools like SentinelOne, Defender, CrowdStrike, Mimecast, CyberArk, Azure, and M365.
  • Comfortable with scripting (PowerShell ideally) and confident writing documentation and presenting to both technical and non-technical stakeholders.
  • Good understanding of frameworks such as NIST, ISO27001, CIS, GDPR, and OWASP.
  • Knowledge of SIEM tools like Splunk, QRadar, or Sentinel.
  • Comfortable working flexibly — some maintenance/change work may fall outside normal business hours.
  • Degree in Computer Science, Cybersecurity, or related field.
  • Certifications such as CISSP, CEH, OSCP, SANS, or ISACA are highly desirable.

Salary (Rate): £90,000.00 yearly

City: London

Country: United Kingdom

Working Arrangements: hybrid

IR35 Status: fixed-term

Seniority Level: undetermined

Industry: Legal

Detailed Description From Employer:

Location: London (Hybrid – 2 days in-office)

Contract: 12-month Fixed Term Contract

Role: Security Engineer

Sector: Legal / Financial Services / Regulated Environments

I’m currently working with a top-tier law firm that’s looking to bring a Security Engineer on board for a 12-month FTC. The role sits within a well-established InfoSec function and reports directly to the Information Security Operations Manager. You’ll play a key role in delivering a range of strategic security initiatives — from tool implementation to enhancing the overall security posture of the firm. This is a fantastic opportunity for someone with a solid technical background in security operations who enjoys both hands-on engineering and contributing to wider strategic security improvements.

What You’ll Be Doing:

  • Supporting the InfoSec team to drive continuous improvement across security operations.
  • Delivering secure designs and implementations for key security maturity projects.
  • Integrating new security technologies and automating routine security processes.
  • Working closely with IT and Development teams to embed security-by-design principles.
  • Running vulnerability scans, patching, and managing threat responses.
  • Managing security tooling – from DLP and SIEM to EDR, IAM, and more.
  • Supporting incident, change, and problem management workflows.
  • Documenting technical designs and representing InfoSec in key governance forums.

What They're Looking For:

  • Proven experience in a Security Engineer role within a legal, financial services, or similarly regulated environment.
  • Strong technical expertise across network, cloud, and endpoint security.
  • Hands-on experience with tools like SentinelOne, Defender, CrowdStrike, Mimecast, CyberArk, Azure, and M365.
  • Comfortable with scripting (PowerShell ideally) and confident writing documentation and presenting to both technical and non-technical stakeholders.
  • Good understanding of frameworks such as NIST, ISO27001, CIS, GDPR, and OWASP.
  • Knowledge of SIEM tools like Splunk, QRadar, or Sentinel.
  • Comfortable working flexibly — some maintenance/change work may fall outside normal business hours.

Ideal Background:

  • Degree in Computer Science, Cybersecurity, or related field.
  • Certifications such as CISSP, CEH, OSCP, SANS, or ISACA are highly desirable.