Haystack
← Back to Jobs
Temporary/Casual
Technology
ET

Cyber Security, Vulnerability Management, Enterprise Security, DevSecOps, Third Party Risk Managemen

EtonwoodUnited Kingdom🇬🇧United KingdomPosted 10 Sept 2026

Quick Overview

Seniority
Mid Senior
Employment type
Temporary/Casual
Work mode
Hybrid
Location
United Kingdom
GCPAWSOWASPAzureGDPRGitHub ActionsGitLab CIJenkins

Job Description

Cyber Security Engineer is required to work on a freelance contract for a global enterprise. The cyber security engineer will possess the following skills and be available immediately for work.

Senior Cyber Engineer - Consultant Profile

Background

Within a large-scale enterprise cybersecurity landscape, this consultant role supports a wide range of security engineering and assessment activities across multiple digital products and platforms, hosted both in the cloud and on-premises. The focus is on making security a built-in quality aspect by working closely with product, platform, and architecture teams to embed security by design, rather than adding it as an afterthought.

The scope of the consultant services is to assist the business in:

1) Enterprise application security

- Identifying and onboarding applications into the security governance model.

- Supporting threat modelling, and security gate checks for key products.

- Helping create simple dashboards and metrics that show security and privacy posture.

2) Vulnerability management

- Onboarding cloud and on-prem assets into vulnerability management tools.

- Supporting risk-based triage and prioritisation of vulnerabilities with clear SLAs.

- Contributing to patching and hardening initiatives and reporting on key metrics (aging, trends, severity).

3) DevSecOps & Runtime Security

  • Help teams embed security controls and checks into CI/CD pipelines and define practical security quality gates.
  • Support and lead security assessments for key applications and platforms.
  • Improve endpoint, network and identity security in collaboration with engineering and operations teams.
  • Contribute to resilience and recovery planning so critical services can withstand and recover from cyber incidents.

4) Third-party Risk management

- Supporting a lightweight intake process for third-party and vendor solutions.

- Reviewing vendor security documentation against security expectations.

- Helping run recurring gate checks so that security, privacy and compliance requirements are met before and after go-live.

Desired knowledge, experience, competence, skills etc

- 7+ years of experience in cybersecurity/security engineering roles in medium to large organisations.

- Hands-on experience with security engineering across cloud and on-prem infrastructure (eg Azure, AWS or GCP).

- Good understanding of application security and common vulnerabilities (OWASP Top 10) and experience with basic security testing or pen testing.

- Practical experience integrating security into CI/CD pipelines (GitHub Actions, GitLab CI, Jenkins or similar).

- Experience with vulnerability management tools and risk-based triage (using CVSS, CISA KeV or similar scoring).

- Familiarity with key frameworks and regulations (for example NIST CSF, ISO 27001, NIS2, GDPR, PCI-DSS).

- Ability to translate technical security findings into clear, actionable guidance for engineers and product teams.

- Collaborative mindset and experience working with cross-functional teams (product, engineering, operations, risk).

- CISSP

What 3 things are most important?

1. Strong practical experience with vulnerability management and infrastructure security (cloud and on-prem).

2. Proven ability to design and operationalize security gate-check processes and intake frameworks to support risk assessments for both internal and third-party products.

3. Capability to translate security risks and findings into clear, prioritised actions for product and platform teams.

Similar jobs