The leader in people-centric cyber resilience.
Cyber Security Engineer – Incident Response, Crisis Simulation
Location
United Kingdom
Posted
17 days ago
Salary
0
Seniority
Senior
Job Description
Cyber Security Engineer – Incident Response, Crisis Simulation
Immersive Labs
• Utilising knowledge of blue teaming engagements and techniques to plan, write and improve defensive security labs, challenges and online learning content on the Immersive One platform. • Produce multi-format content utilising various teaching methods; practical exercises, questions & gamification • Test Blue Team labs and ranges to ensure they function as expected • Research the latest crisis and incidents and compile this research to deliver a catalogue of crisis simulation content • Compile technical research into understandable concise content for both technical and non-technical audience • Work with the wider Product team on new projects and product innovations and how best to deploy them
Job Requirements
- A number of years of experience working in the defensive security space, particularly within Incident Response or table top exercises
- In-depth knowledge of the MITRE ATT&CK framework and how it is used to help enterprises deal with threats to their organisation.
- Have a strong technical understanding of networking, computing and cyber security concepts
- Have the ability to use examples and analogies to simplify complex subjects - your content will train real world users to identify and combat the latest threats so you need to be able to inhabit the mindset of your target audience to create realistic simulations
- Attitude and approach is just as important as technical skills for this role - you will be someone who enjoys tackling complex problems and finding the solution. You'll be a natural problem solver and 'tinkerer' who enjoys prototyping and iteration.
Benefits
- Time off, flexible and remote working so you can work when is best for you, includes 25 days annual leave + 2 volunteering days and your birthday off
- The longer you are with Immersive, the more holiday days you get, up to a maximum of 30 days after five years of service
- Look after your family and yourself with enhanced parental leave, mindfulness groups, critical illness cover, 7% matched pension, private healthcare plan and more
- Career and learning development through the platform, a dedicated professional development fund and our ‘Learn Anything’ fund - which enables you to learn anything that’s not work!
- Recognition & Rewards for doing great work and living our values and behaviours
- Informal or formal flexible working options, e.g. flexible start and finish times, reduced hours
- We have a vibrant team culture with team events throughout the year. Our socials have included everything from pottery painting and paper mask making, to dungeons and dragons!
- When you do visit the UK hub, getting there is easy: we’re based in the centre of Bristol, just a 10 minute walk from the train station. We also offer railcard loan and cycle scheme to buy a new bike
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide - including Brex, Rippling, Navan, Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale. Proudly founded in Melbourne, we have a team of over 2,200 of the brightest and most innovative people in tech across 26 offices around the globe. Valued at US$8 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you're ready to do the most ambitious work of your career, join us. Attributes We Value We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you're motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor. You're humble and collaborative; turn zero-to-one ideas into real products, and you "get stuff done" end-to-end. You use AI to work smarter and solve problems faster. Here, you'll tackle complex, high-visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let's build what's next. About the team Airwallex's Information Security team partners closely with engineering, IT, and other stakeholders to protect our systems, data, and employees while enabling the business to move quickly. The team helps build and maintain strong security practices across the company-from secure product and infrastructure design to risk reduction, incident response, audits, and compliance-so security is built into how we operate, not treated as a blocker. Your role As a Staff Product Security Engineer at Airwallex, you will be a trusted member of the Information Security team and work closely with Infrastructure, Product and Engineering teams across the business. Reporting directly to the Product Security Engineering Manager, this role will see you being a critical part of Airwallex, helping to identify, protect, detect, respond and recover the organisation from cybersecurity threats. This is a dynamic and hands-on role that requires experience in designing, developing and managing infrastructure projects, processes and standards related to the security of our networks, systems and applications. What you'll be doing - Create and build security controls that strengthen Airwallex's ability to scale securely. - Design and deliver security improvements across applications, software, and services. - Develop and operationalise detection strategies and response workflows that improve the speed and effectiveness of incident response. - Build and enhance secure systems through strong integration, testing, operations, and maintenance practices. - Leverage and analyse endpoint, network, and cloud telemetry to identify, investigate, and mitigate threats. - Design, implement, and maintain cybersecurity infrastructure that improves resilience across the Airwallex environment. - Investigate, contain, and respond to cybersecurity incidents to reduce risk and strengthen defensive capability. - Assess and improve system and network security by identifying vulnerabilities, configuration issues, and remediation opportunities. - Collect and analyse threat intelligence and forensic evidence to better understand, track, and disrupt threats. - Conduct and support defensive operations, tactical forensics, and threat hunting to strengthen security outcomes. - Partner with teams across Airwallex to embed security into new and existing applications, software, and services and drive continuous improvement. Minimum Qualifications (must-have) - 8+ years working in a security engineering or incident response role within a tech company - In depth expertise with at least one major cloud platform - Strong knowledge of common software development tools and infrastructure, including CI/CD tooling and pipelines - Comprehensive understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation - Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience - A passion for solving the complex challenges of high-growth startups - Self motivation and drive to learn new skills, or dive deeper into existing skills Highly Desired - Bachelor's degree in Cybersecurity, Computer Science or similar - Recognised training or cybersecurity certifications (eg OSCP, GIAC, CEH) - Strong experience with Splunk and other common security monitoring tools - Past DevOps/SRE experience with Kubernetes - Experience with GCP or Alibaba Cloud (with or without certification) - Experience with Okta, GSuite, and cloud-based VPN services - Experience with Python, Java/Kotlin - Published articles, journals or blogs related to cybersecurity Applicant Safety Policy: Fraud and Third-Party Recruiters To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page. Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary. Equal opportunity Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don't regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know. #BI-Hybrid
• Partner with product and engineering teams to integrate security throughout the development lifecycle and drive security initiatives across our stack. • Leverage AI and automation to scale product security coverage, matching the pace of AI-assisted development across engineering. • Design and implement security controls and architecture that scale with our growing product portfolio. • Conduct comprehensive security reviews and threat modeling to identify and mitigate potential vulnerabilities, including risks introduced by AI-generated code and AI-powered features. • Contribute to our vulnerability management program, including triaging bug bounty and vulnerability disclosure reports and driving remediation efforts. • Develop and implement automated security testing, monitoring, and response capabilities, using Tines itself, plus AI-driven tooling, to eliminate manual toil. • Serve as an incident responder during security events and lead post-incident reviews. • Champion security awareness and provide technical guidance to engineering teams, including best practices for secure AI-assisted development.
Security Engineer
GoDaddyGoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a
Role Description Join GoDaddy’s Product Security group as a Security Engineer. In this remote position, you will work from home while occasionally visiting a GoDaddy office for team events or meetings. You will be responsible for: - Identifying security threats and vulnerabilities in applications and infrastructure and providing remediation mentorship to system owners. - Collaborating with SRE and development teams to discover and implement creative ways to reduce the occurrence of vulnerabilities at scale. - Developing repeatable and reusable security processes and frameworks. - Advocating for secure by build and secure by default development strategies. - Reviewing quality issues and striving to detect both obvious and subtle security flaws. - Assisting with prioritizing prospective projects and participating in projects from kickoff through “definition of done” via end-to-end ownership. - Applying your industry experience to own and drive resolution and retesting of complex security events, policy questions, and technical security risks. Qualifications - 1+ years of progressive security engineering experience with expertise in multiple security domains, including but not limited to Security Architecture, Cryptography, Network Security, Cloud Security, Mobile Security, and Web Security. - Demonstrated problem-solving abilities combined with a strong technical grasp of security engineering. - Experience in threat modelling complex software services, secure code review, and penetration testing. - Solid knowledge of security controls across all layers of the OSI model related to common technologies. - Experience applying security engineering guidelines that align with security and privacy compliance requirements. Requirements - Bachelor's degree (preferred). - Experience in Secure Development Lifecycle and Shift Left with a Security by Build methodology. - Proficiency in system architecture and building, scripting/development skills (e.g., Python, C, C++, Java, Ruby, or PowerShell). - Hosting Industry and/or Cloud Experience. - Hardware security experience. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Family-friendly benefits including parental leave. Company Description GoDaddy is empowering everyday entrepreneurs around the world by providing the help and tools to succeed online, making opportunity more inclusive for all. Our mission is to give our customers the tools, insights, and people to transform their ideas and personal initiative into success. - We know diverse teams build better products. - We prioritize integrating diversity, equity, inclusion, and belonging principles into the core of how we work every day. - GoDaddy is proud to be an equal opportunity employer.
• Lead the design, implementation, and governance of SAP security across S/4HANA, SAP BTP, Fiori, and associated cloud platforms. • Manage user access administration, provisioning, lifecycle management, and identity integration using SAP Cloud Identity Services (IAS/IPS). • Design and maintain SAP roles and authorisations, ensuring secure and compliant access aligned with business requirements. • Drive Segregation of Duties (SoD) governance, risk analysis, mitigation strategies, and audit remediation activities. • Support incident and security management processes, investigating access-related issues and implementing corrective actions. • Provide security architecture guidance across SAP projects and enhancement programs, embedding security-by-design principles. • Lead and support the transition from legacy Identity Management solutions to SAP Identity Access Governance (IAG). • Collaborate with business, Basis, architecture, and audit teams to deliver secure, scalable, and compliant SAP solutions. • Ensure security controls and governance are maintained across hybrid SAP environments, including BTP, SAC, Datasphere, BW, and related platforms.




