Security Engineer
New Today
Netcraft Manchester, England, United Kingdom
3 days ago Be among the first 25 applicants
Get AI-powered advice on this job and more exclusive features.
About Netcraft
Netcraft is the global leader in cybercrime detection and disruption. We’re a trusted partner for three of the four largest companies in the world and many large country governments. We’ve blocked more than 200 million malicious sites and perform takedowns for around one-third of the world’s phishing sites.
Our purpose, passion, and expertise are focused on just one thing: protecting the world from cybercrime.
Our passion doesn’t stop at what we do—it shapes how we work, too. We’re proud of our talented team and the value each person brings. That’s why we’ve created a workplace where people feel supported and inspired, from great benefits and wellness programs to fun social events.
The Role
We are searching for a Security Engineer to join our growing engineering team. Based in either London, Manchester, or Bath, you'll report to our Engineering Team Lead in the Security team, part of the Platform Engineering department. You will work within a team to build and maintain security tooling to help improve internal security capabilities across our platforms.
Netcraft’s Engineering division maintains a wide range of services, from modern Go-based applications that run in Kubernetes to twenty-year-old Perl-based systems that run directly on Linux servers. We use AWS for our customer-facing workloads, both directly on EC2 and on managed services such as RDS, EKS, ElastiCache, OpenSearch, S3, RabbitMQ, Security Lake, and more, running at scale with a high degree of automation: taking down a malicious site from the internet every 12 seconds, classifying 20 million URLs a day, and inspecting 1.2 billion sites every month.
This role will give you the opportunity to work collaboratively both within the Platform Engineering department and across the Engineering division to help us to continually improve our internal security and to enable teams to secure their systems. Your day-to-day work will involve developing internal security tooling and security-related CI/CD pipelines, supporting maintenance of security infrastructure in AWS, and investigating and responding to security incidents.
What You'll Be
- Designing, developing, and maintaining internal security tooling for use by both the Security team and the wider Engineering division.
- Taking ownership of security-related CI/CD pipelines, including SCA tooling (Black Duck) and SAST scanning.
- Collaborating with other Engineering teams to enable them to secure the systems they develop.
- Helping respond to security alerts and incident investigations, including as part of our on-call rota once you are familiar with our systems.
- Testing and documenting your work to a high standard.
- Working with cross-functional stakeholders to help propose, design and implement solutions to meet business needs, as well as to champion security best-practices.
- Advocating for and implementing improvements to the Netcraft developer experience, leveraging your skills and experience to add value that doesn’t necessarily relate to Security.
What You Need To Be Successful
- A keen interest in cybersecurity and a love of automation.
- Commercial experience programming in Go or similar languages.
- Commercial experience deploying, using, and tuning DevSecOps tooling, such as SAST/DAST scanners and SCA tools.
- Experience with modern CI/CD pipeline development, ideally in developing and helping roll out pipelines that are designed to be used across multiple projects.
- Experience using cloud providers, such as AWS, including their infrastructure and managed services.
- Experience responding to security-related incidents and writing retrospectives.
- Strong technical communication skills; especially the ability to explain your reasoning to Engineers across the division.
Bonus Points
- Experience with the GitLab DevOps stack, especially in CI/CD.
- Exposure to Infrastructure-as-Code technologies, ideally Terraform.
- Exposure to configuration management tools such as Puppet.
- Exposure to Kubernetes (especially hosted on AWS EKS) and Docker or other containerization technologies, with even more bonus points if your exposure extends to cluster security.
- A keen interest in cybercrime disruption and internet security.
- Experience with AWS security tooling, such as Security Lake, GuardDuty, CloudTrail, CloudWatch, Config or similar.
- Exposure to Microsoft 365 security tooling, such Defender or Entra.
- Experience supporting external security audits (such as SOC 2 or ISO 27001) through evidence-gathering and walkthroughs.
The reward package
An Excellent Range Of Benefits Including
- Hybrid working: two days per week in the office, with flexibility to agree which days with your manager and vary these from time to time as needed.
- Minimum of 33 days holiday per annum (incl. public holidays)
- Pension scheme membership with 4% employer contributions + NI savings
- Private health cover, including access to a private GP service
- Equity tracking scheme, so you can share in the rewards of Netcraft's long-term success (eligibility criteria apply)
- Comprehensive wellness and support provisions
- Enhanced family leave provisions
- Life Assurance
- Two days paid Volunteering Leave per year
- Free meals, drinks and snacks provided daily in the offices
- Regular social events such as board game nights, big summer party and annual kick-off
- Inclusive culture and environment, where you’ll feel genuinely valued and respected
- A tax-efficient cycle to work scheme.
Diversity, Equity and Inclusion
This is very important to us and through our ally network we support under-represented groups. We seek to maintain a working environment that is free from bias, harassment or discrimination, and we encourage candidates from any background to apply, regardless of their gender, gender identity, sexual orientation, race/ethnicity, ability/disability, age, religion, or any other specific characteristics.
We’re happy to make adjustments to our hiring process to ensure that all candidates can participate fully and comfortably.
Please note Netcraft does not accept any unsolicited approaches from external recruiters.
- Location:
- Manchester, England, United Kingdom
- Salary:
- £125,000 - £150,000
- Job Type:
- FullTime
- Category:
- IT & Technology
We found some similar jobs based on your search
-
New Today
Senior Security Engineer
-
England, United Kingdom
-
£100,000 - £125,000
- Engineering
This range is provided by Crone Corkill. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range Direct message the job poster from Crone Corkill Is this the Senior Security Engineer role...
More Details -
-
New Today
Senior Security Engineer (Product Security)
-
London, England, United Kingdom
-
£150,000 - £200,000
- Engineering
Overview Ebury is a fintech company seeking a Senior Security Engineer (Product Security) to embed security throughout the product development lifecycle. You will work with engineering teams to identify and mitigate security risks through threat mod...
More Details -
-
New Today
Senior Azure Cloud Security Engineer
-
Welwyn Garden City, England, United Kingdom
-
£100,000 - £125,000
- Engineering
Join to apply for the Senior Azure Cloud Security Engineer role at Tesco Technology About the role Join as an Azure Cloud Security Engineer within the infrastructure security architecture team. Your core purpose will be acting as the go-to subject...
More Details -
-
New Today
Installation Engineer (Security / AV Systems)
-
United Kingdom
- Engineering;Engineering
Installation Engineer (Secuirty / AV Systems) Salary: £35,000 - £45,000 + Company Van + Training + Progression. Location: Location: Ealing (Commutable from: Greenford, Northolt, Wembley, Harlesden, Harrow, Hayes). Fantastic opportunity for an Instal...
More Details -
-
New Today
Lead Firewall Security Engineer
-
United Kingdom
-
£80,000 - £100,000
- Other
Overview Job Title: Lead Firewall Security Engineer (8+ Years of experience) Location: Remote Visa: No Student / No PSW Visa What we're looking for SOC / Threat / Forensics or CSIRT backgrounds — highly experienced at analyzing security logs...
More Details -
-
New Today
Cloud Security Engineer (Automation & Tooling) - Engine by Starling
-
London, England, United Kingdom
-
£125,000 - £150,000
- Engineering
Overview At Engine by Starling, we are on a mission to find and work with leading banks around the world who have the ambition to build rapid growth businesses on our technology. Engine is Starling's software-as-a-service (SaaS) business, the techno...
More Details -