HomeJobsHuntingdonCyber Security Engineer
Back to all jobs
⚡ Source: ReedRef: 57040679

Cyber Security Engineer

Appcast Enterprise·Huntingdon·Posted 8h ago
🏢 On-site
Tailor my CV for this job — Free

Job description

Original text imported from Reed

Description

Cyber Security Engineer

Security Clearance Required - DV ('Developed Vetting')

Location: Huntingdon, UK (On-site 4/5 days a week)
 

UNLEASH YOUR POTENTIAL

At Leidos, we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customers’ success. We empower our teams, contribute to our communities, and operate sustainably. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.

Are your ready for your next challenge?

We are in search for multiple Cyber Security Engineers with varying technical backgrounds - Required to work at our customer site in Huntingdon, Cambridgeshire with occasional travel to other UK sites.  In this role, you will working within a team of engineers to ensure that the customer sites maintain a strong cyber security posture.

Cyber Security Engineers are responsible for providing cybersecurity engineering services for classified and unclassified networks of computer systems.  The Cyber Security Engineers will provide operational and engineering support.

This position perform the following tasks:

  • Develop creative solutions to complex technical issues and problems

  • Work with the engineering teams to ensure systems remain at the required security posture against baseline requirements

  • Work with the Security Monitoring engineering team to ensure logs are forward to the SIEM capability

  • Work with the customer and appropriate agencies to develop new policies, design processes, and procedures, and develop technical designs

  • Assess system vulnerabilities, implement risk mitigation strategies, validate secure systems, and test security products and systems to detect security weakness

  • Maintain and support security enforcing functions

Core Skills

  • Experience working in MOD or Home Office project environments

  • Strong knowledge of network and system security, including firewalls, IDS/IPS, micro-segmentation, and host security.

    • Hands on experience with the following security products Trellix, Ivanti, ClearSwift, Yubikey

  • Understanding of secure coding practices and common vulnerabilities (OWASP Top 10, SANS Top 25).

  • Expertise in identity and access management (IAM), including RBAC, ABAC, JWT and Cookie based authentication.

  • Incident detection and response in MOD environments.

  • Security compliance and regulatory frameworks (e.g., NIST, CIS Benchmarks).

  • Experience working with Kubernetes at an administrative level

Soft Skills

  • Strong leadership and mentoring abilities.

  • Effective communication with development, operations, and security teams.

  • Ability to advocate for security best practices in a DevOps culture.

Desirable Skills

Containerization Security

  • Expertise in Kubernetes security (e.g., RBAC, network policies, pod security standards, secrets management).

  • Knowledge of container runtime security (e.g., container escapes, rootless containers, sandboxing).

  • Image security best practices, including scanning, signing, and provenance verification.

  • Secure deployment patterns using Tanzu & Kubernetes.

  • Runtime security monitoring.

DevSecOps & CI/CD Security

  • Secure CI/CD pipeline design with security testing using like Git and SonarQube.

  • Implementation of Infrastructure as Code (IaC) security (e.g., Terraform, Ansible).

  • Secrets management in CI/CD pipelines using Vault or Kubernetes Secrets.

  • Security automation and policy enforcement using tools like GitHub Actions, GitLab CI and Jenkins.

Cloud & Infrastructure Security

  • Strong knowledge of cloud security principles in a containerised environment.

  • Kubernetes security posture management (KSPM) using tools like Trivy.

  • Secure ingress/egress controls, service mesh security (e.g., Istio).

  • Encryption strategies for data at rest, in transit, and in use.

  • Network security best practices for Tanzu container networking (e.g., NSX, Rancher)

  • Compliance monitoring and security auditing for cloud-native environments.

Automation & Scripting

  • Scripting skills in Python, PowerShell for security automation.

  • API security knowledge (e.g., OAuth, JWT, API gateways, rate limiting).

  • Experience with Security as Code for automated policy enforcement.

Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your CV with us today!

What we do for you:
At Leidos we are PASSIONATE about customer success, UNITED as a team and INSPIRED to make a difference. We offer meaningful and engaging careers, a collaborative culture, and support for your career goals, all while nurturing a healthy work-life balance.

  • We provide an employment package that attracts, develops and retains only the best in talent. Our reward scheme includes:

  • Contributory Pension Scheme

  • Private Medical Insurance

  • 33 days Annual Leave (including public and privilege holidays)

  • Access to Flexible benefits (including life assurance, health schemes, gym memberships, annual buy and sell holidays and a cycle to work scheme)

  • Flexi-TIme


Commitment to Diversity:

We welcome applications from every part of the community and are committed to a truly diverse and inclusive culture.  We foster a sense of belonging, welcoming all perspectives and contributions, and providing equal access to opportunities and resources for everyone.  If you have a disability or need any reasonable adjustments during the application and selection stages please let us know, and we will respond in a way that best fits your needs.

Who We Are:

Leidos UK & EUROPE – we work to make the world safer, healthier, and more efficient through technology, engineering and science.

Leidos is a growing company delivering innovative technology and solutions focused on safeguarding critical capabilities and transformation in frontline services, our work in the United Kingdom includes addressing some of the most complex problems in defence, healthcare, governme
SpeedCV AI

Key skills

AI-extracted from the job advert

Must-have skills
DV (Developed Vetting) security clearanceMOD or Home Office project environment experienceFirewall, IDS/IPS and micro-segmentationTrellix, Ivanti, ClearSwift, YubiKeyOWASP Top 10 / SANS Top 25IAM including RBAC and ABACSIEM log forwarding and integrationNIST and CIS Benchmarks complianceKubernetes administration
Nice-to-have
Kubernetes RBAC and network policiesPod security standards and secrets managementContainer runtime security (rootless containers, sandboxing)Container escape mitigation techniques
Soft skills
LeadershipMentoringCommunicationAdvocacy for security best practicesCross-team collaboration
SpeedCV AI

Application advice

5 AI-generated recommendations to maximise your chances.

1

⭐ Highlight your MOD or Home Office project experience prominently in your Personal Statement — the advert lists this as the first core skill requirement.

2

📊 Quantify your security impact: e.g. "Reduced vulnerability exposure by 40% across 3 classified networks by implementing CIS Benchmark hardening."

3

🔐 Explicitly list your DV (Developed Vetting) clearance status in your CV header or a dedicated 'Security Clearance' line — this is a hard requirement and recruiters scan for it immediately.

4

🛠️ Dedicate a 'Tools & Technologies' section to the named products: Trellix, Ivanti, ClearSwift, and YubiKey — ATS systems will be filtering for these exact terms.

5

🐳 If you have Kubernetes security experience (RBAC, pod security standards, secrets management), place it in a dedicated subsection under skills — the advert flags this as both a core and desirable requirement.

NEW
AI SpeedCV

Suggested CV bullets

3 bullets our AI drafted for this specific advert, mirroring its ATS keywords.

How to tailor your CV

Add these 3 bullets under your most recent experience:

  • Administered Kubernetes clusters across 3 classified MOD environments, implementing RBAC, pod security standards and secrets management to achieve CIS Benchmark Level 2 compliance.
  • Led integration of 12 log sources into a Splunk SIEM platform, reducing mean time to detect (MTTD) security incidents from 4 hours to 45 minutes across unclassified and classified network segments.
  • Delivered OWASP Top 10 vulnerability assessments across 8 web-facing applications within a DevSecOps pipeline, remediating 94% of critical findings within a 6-week sprint cycle.

Free to copy — tailoring requires a 30-sec CV upload.

NEW
AI cover letter

Your cover letter is ready

We've drafted a cover letter for Appcast Enterprise. Preview the opening, then unlock the full personalised version.

Letter preview — tailored to Appcast Enterprise

Dear Hiring Manager,

Leidos' work securing classified MOD networks is precisely the environment where I want to apply my expertise — which is why the Cyber Security Engineer position in Huntingdon immediately stood out. With hands-on experience in SIEM integration, Kubernetes administration, and IAM frameworks including RBAC and ABAC, I am well positioned to contribute to the security posture of your customer sites from day one.

My background in cyber security engineering spans classified government environments, where I have implemented CIS Benchmark hardening across mixed network estates, led incident detection and response workflows, and worked directly with stakeholders to develop security policies aligned to NIST frameworks. I have deployed and maintained security tooling including Trellix and Ivanti, and have experience forwarding logs to SIEM platforms to support continuous monitoring.

Get my personalised letter — free

Free signup, no card needed. Export to PDF/Word requires a £1.99 trial (14 days).

SpeedCV exclusive
SpeedCV AI

Interview questions

10 questions generated from this advert.

Technical

  • Walk us through how you would integrate a new log source into a SIEM and validate that alerts are firing correctly in a classified MOD environment.
  • How would you implement micro-segmentation across a mixed classified and unclassified network, and what tools would you use?
  • Describe your approach to hardening a Kubernetes cluster in line with CIS Benchmarks, including RBAC and pod security standards.
  • How do you assess and mitigate vulnerabilities identified in the OWASP Top 10 within a DevOps pipeline?
  • Explain the difference between ABAC and RBAC in an IAM context and give an example of when you would choose one over the other.

Behavioural

  • Tell me about a time you identified a critical security weakness in a system and had to persuade a reluctant team to remediate it quickly.
  • Describe a situation where you had to develop a new security policy or procedure from scratch in collaboration with a customer or external agency.
  • Give an example of a complex incident you led the response to — what was your process and what was the outcome?
  • Tell me about a time you mentored a junior engineer on security best practices. How did you measure their progress?
  • Describe a situation where you had to balance security requirements against operational deadlines in a government or defence environment.
SpeedCV AINEW

STAR answer examples

Model answers using the Situation-Task-Action-Result framework. Adapt to your own experience.

1Question

Tell me about a time you identified a critical security weakness in a system and had to persuade a reluctant team to remediate it quickly.

Situation: During a routine CIS Benchmark audit on a government network, I identified that 3 critical servers had outdated TLS 1.0 configurations still enabled, exposing them to POODLE-style downgrade attacks. Task: The infrastructure team was mid-sprint and resistant to unplanned changes. Action: I produced a one-page risk brief quantifying the exposure, mapped it to the NIST SP 800-53 control framework, and escalated to the security lead with a proposed 4-hour remediation window. I offered to pair with the infrastructure engineer to minimise disruption. Result: The fix was implemented within 48 hours, the audit finding was closed, and the team adopted a quarterly TLS configuration review as standard practice.
2Question

Describe a situation where you had to develop a new security policy or procedure from scratch in collaboration with a customer or external agency.

Situation: A MOD customer site lacked a formal removable media control policy, creating an audit gap ahead of an annual accreditation review. Task: I was tasked with drafting and gaining sign-off on the policy within 6 weeks. Action: I facilitated 3 workshops with the customer's IT security officer and the accreditor, benchmarked the draft against JSP 440 and CIS Controls v8, and iterated through 2 review cycles incorporating 14 separate comments. I also produced a 1-page user-facing summary to support rollout. Result: The policy was approved 5 days before the accreditation deadline, received no major findings during review, and was adopted as a template for 2 additional sites within the same programme.

Similar jobs

View all