Platform Security Engineer
Canary Wharf, UK
Hybrid (2 days a week)
Long Term Contact (Inside IR35)
Required Skills & Experience
Technical
• 3–5 years of experience in DevSecOps, platform security, or information security engineering roles.
• Hands-on experience building SCBs for enterprise DevOps and collaboration tools (Bitbucket, Bamboo, Jenkins, Nexus, Jira, Confluence, SonarQube, Mend, or equivalent).
• Strong working knowledge of NIST CSF v2.0, OWASP Security Controls, and ISO 27001/27002.
• Experience conducting configuration assurance reviews, control gap assessments, and risk-based remediation planning.
• Familiarity with GDPR, NIS2, DORA, or equivalent regulatory frameworks and their impact on platform configuration.
• Experience writing Incident Response Playbooks or security runbooks aligned to NIST or SANS frameworks.
Delivery & Communication
• Proven ability to lead security engagements end-to-end — planning, stakeholder reporting, and delivery ownership.
• Able to bridge technical and non-technical audiences, turning complex security requirements into engineering actions.
• Experience with Agile delivery; proficient in JIRA for backlog and sprint management.
• Strong documentation skills — able to produce clear SCB documentation, audit evidence packs, and executive-level reports.
Preferred Qualifications (Not Mandatory)
• ISO 27001 Lead Auditor or Lead Implementer certification.
• CISA (Certified Information Systems Auditor) or equivalent.
• CIPM (IAPP) or other data privacy certifications.
• Experience in Financial Services or other regulated industries.
What We're Looking For
The ideal candidate takes full ownership of platform security from day one. You have built SCBs before, know how to drive remediation across engineering teams, and can hold your own in conversations with both developers and senior stakeholders. You'll be joining a mature programme and are expected to sustain, challenge, and improve it.
Discovering Direct IT Contract Opportunities for Contract Spy members.