Senior Vulnerability Management Engineer

🕒 il y a 1 mois

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟠 Senior

👷🏻‍♀️ Ingénieur

👻 Score fantôme 18%

infoinfo

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of LSEG (London Stock Exchange Group)

LSEG (London Stock Exchange Group)

10 000+ employés

💸 Finance

💳 Fintech

🤝 B2B

Finance • Fintech • B2B

LSEG (London Stock Exchange Group) est une entreprise diversifiée d'infrastructures de marché international – gagnant la confiance de nos clients depuis plus de 300 ans. Cet héritage d'excellence axée sur le client garantit que vous pouvez compter sur notre expertise en matière de formation de capital, de propriété intellectuelle et de gestion des risques et du bilan.

Description

• Analyze and review penetration test reports to understand technical impact, exploitability, and business risk. • Develop, document and maintain remediation guidance, patterns, and blue-prints for common vulnerability types (e.g. injections, access control, auth, session management, misconfigurations). • Provide consultation to application and platform teams on secure design and remediation approaches, including code-level, configuration-level and business-level recommendations. • Coordinate remediation activities across multiple teams, ensuring, clear ownership, agreed timelines, and risk-based prioritization. • Validate fixes by retesting vulnerabilities (manually and/or via tools/scripts) and updating the status of findings through closure. • Manage and track the remediation backlog, including SLAs, aging findings, and critical issues when needed. • Produce and maintain documentation on remediation processes, workflows, and controls for audit and compliance purposes. • Prepare and deliver regular status reports and metrics on remediation progress, trends, and risk reduction to management and partners. • Perform root cause analysis for recurring or systemic issues and work with engineering, architecture, and governance teams to implement long-term corrective actions. • Contribute to continuous improvement of the pentest-to-remediation lifecycle, including automation, standardization and integration with SDLC/DevSecOps pipelines. • Compile technical documents, track and document remediation metadata Engagement details (who, what, when, where) Testing team members and roles Tools and methodologies used Schedule and timelines Target systems and environments Constraints, exclusions, and limitations Testing activities and event logs. • Contribute to team improvement efforts and ensure all initiatives and feedback are well documented for future references. • Contribute to the continuous improvement of testing methodologies, tooling, automation. • Stay ahead of with emerging threats, vulnerabilities, and offensive security techniques. • Participate in R&D initiatives as guided from leadership. • Support knowledge sharing and mentoring within the team.

🎯 Exigences

• Proven hands-on experience in penetration testing of Web Applications, APIs, Thick Client and Common Infrastructures (Active Directory, Cloud and Cloud-native based environments). • Proficiency with tools such as Burp Suite, common command-line tools, and ability to write custom scripts when needed. • Experience in automating pentesting tasks. • Solid understanding of application security, network protocols, and operating systems. • Experience with cloud platforms (AWS, Azure, GCP) and containerized environments (Docker, Kubernetes). • Solid understanding of common vulnerabilities and exposures (OWASP Top 10, SANS Top 25) and secure coding practices in at least one major language stack (e.g. Java/ Springboot , .NET, JavaScript/Node, Python) • Ability to write clear, technical reports and communicate findings and fixes to both technical and non-technical partners. • Experience working in large, complex enterprise environments. • Proficient communication skills in English, both written and verbal. • Relevant certifications and engagement with the security community is a plus. • Threat Modelling experience is a plus. • Proven track record of successfully managing and driving security engagements for various organizations with differing operational and technical profiles. • Ability to identify, assess, and communicate technical and project risks to partners. • Understanding project requirements and aligning work with agreed upon objectives and timelines.

🏖️ Avantages

• Healthcare • Retirement planning • Paid volunteering days • Wellbeing initiatives

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

Zencargo

201 - 500

📦 Logistique

🚗 Transport

☁️ SaaS

Forward-Deployed Engineer at Zencargo solving operational and customer problems with software and AI. Collaborating with various stakeholders to automate freight processes and improve workflows.

🇬🇧 Royaume-Uni – Télétravail

💰 €42 000 000 Series B en 2021-05

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Chalk

51 - 200

🤖 Intelligence artificielle

☁️ SaaS

🤝 B2B

Build bespoke technical solutions and feature pipelines for machine learning applications in healthcare and finance. Collaborate with customers to gather requirements and implement Chalk’s technology.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Reactive Markets

11 - 50

💳 Fintech

🤝 B2B

💸 Finance

ClickHouse Engineer managing a multi-datacentre ClickHouse cluster handling billions of rows daily. Responsible for cluster operations, schema design, ingestion performance, and query optimisation.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis

Amazon Redshift

BigQuery

Grafana

Kubernetes

Linux

Python

SQL

Go

🕒 il y a 1 mois

Atlas Technica

201 - 500

🔒 Cybersecurity

💸 Finance

Senior TechOps Engineer responsible for designing, optimizing, and supporting multitenant solutions for clients. Collaborating with internal teams and providing advanced technical support for operational processes.

🇬🇧 Royaume-Uni – Télétravail

⏰ Temps Plein

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Aira

201 - 500

⚡ Énergie

🏭 Fabrication

👥 B2C

Clean Energy Technician installing Aira's latest heat pumps, cylinders, and radiators to help families lower costs and carbon footprints. Join a team of Engineers making a positive environmental impact from a fully remote location.

🇬🇧 Royaume-Uni – Télétravail

💵 £36 050 / an

💰 €175 090 463 Venture Round - Aira en 2025-08

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👷🏻‍♀️ Ingénieur

🗣️🇺🇸🇬🇧 Anglais requis