Job detail for Security Engineer
Use AI to assess how you fit
Location: Hybrid - primarily remote, with travel to FI centres as required
Contract Type: Permanent, Full-Time
About Us
First Intuition (FI) is a fast-growing, innovative accountancy training provider committed to delivering outstanding learning experiences. At FI, our commitment to excellence is driven by our core driving principle of putting people first. We take pride in nurturing talent, fostering growth, and providing unparalleled support to our students, clients, and team members, ensuring they can thrive personally and professionally.
Our success is due to our approach to training and our links with businesses. We work closely with organisations to precisely understand their needs and incorporate these into innovative course designs, where the interaction with students is tailored, personal and reflects their specific circumstances. This approach has led to First Intuition being awarded an ‘Outstanding’ rating by Ofsted.
We are seeking a hands-on Security Engineer with a strong vulnerability management focus to help reduce organisational cyber risk through effective vulnerability management, security automation and continuous improvement of security controls. This is an excellent opportunity to join a growing security function and play a key role in protecting our rapidly expanding organisation.
You will manage the technical vulnerability lifecycle from identification and validation through risk-based prioritisation, remediation and verification. You will also support security operations by improving the tooling, integrations and automated processes used by the SOC to identify and respond to security threats.
This role suits an engineer who enjoys turning security findings into measurable risk reduction, automating repeatable security processes and working across Security, Infrastructure, IT Operations and application teams.
What You’ll Do
- Operate and continuously improve the end-to-end vulnerability management lifecycle across endpoints, servers, networks, cloud services and applications.
- Run and review authenticated vulnerability assessments using Qualys, validate findings and reduce false positives.
- Prioritise vulnerabilities using exploitability, threat intelligence, internet exposure, asset criticality, business impact and technical severity rather than relying on CVSS alone.
- Translate findings into clear remediation plans with defined owners, target dates and verification criteria.
- Work with system and application owners to remediate vulnerabilities through patching, configuration changes, hardening, upgrades or compensating controls.
- Develop security automation, preferably using Python, to improve vulnerability triage, remediation workflows, data enrichment and fix validation.
- Test, coordinate and validate security patches and configuration changes while balancing security risk and operational impact.
- Support the SOC from an engineering perspective by improving security tooling, integrations, alert enrichment and automated response processes.
- Assist with security investigations where vulnerabilities, insecure configurations or missing patches may have contributed to an event.
- Use threat intelligence to provide context for vulnerability prioritisation, security alerts and emerging threats.
- Apply Zero Trust principles when implementing or improving endpoint, identity, network and cloud security controls.
- Review network-device configurations and firewall rule sets using Nipper Studio or comparable security auditing tools.
- Track vulnerabilities, exceptions and remediation progress through to verified closure.
- Produce security metrics and dashboards covering exposure, vulnerability ageing, remediation performance and residual risk.
- Maintain technical documentation, remediation playbooks and security automation code.
- Carry out tasks as delegated by the Information Systems Security Manager from time to time.
What You’ll Bring
Essential
- Two to three years’ experience in cyber security, security engineering, infrastructure engineering, IT operations or a related technical role.
- Hands-on experience with vulnerability scanning, assessment and remediation using Qualys or a comparable enterprise platform.
- Demonstrable ability to analyse, validate and prioritise vulnerabilities using technical and business risk factors.
- Practical experience driving remediation across Windows, Linux, endpoints, networks, cloud services or applications.
- Scripting capability for security automation. Either Python or PowerShell is strongly preferred, particularly for automating vulnerability identification, triage, remediation and validation procedures.
- An understanding of CVEs, CVSS, known exploited vulnerabilities, threat intelligence, attack paths, security hardening and compensating controls.
- An understanding of security operations, including security monitoring, alert investigation and incident response processes.
- A practical understanding of Zero Trust security principles.
- The ability to manage multiple remediation activities and maintain momentum from identification through to verified closure.
- Strong written and verbal communication skills, with the ability to explain technical risks and remediation requirements to technical and non-technical stakeholders.
- Right to live and work in the UK and ability to travel, when required, to centres.
Desirable
- Experience with Microsoft 365 E5/A5 security technologies, including Defender for Endpoint Plan 2 and Defender for Office 365 Plan 2.
- Experience with vulnerability assessment and management tools, preferably Qualys.
- Experience with firewall and network-security auditing tools, preferably Nipper Studio.
- Experience supporting security operations, SIEM, threat intelligence or incident investigations.
- Experience with Microsoft Intune, Entra ID, Azure or AWS security.
- Relevant certifications, such as Microsoft SC-900 or CompTIA Security+.
What Success Looks Like
- Vulnerabilities are accurately identified, risk-ranked, assigned and remediated within agreed service levels.
- Critical and actively exploited vulnerabilities receive rapid, intelligence-led attention.
- Remediation is technically verified and recurring vulnerabilities are reduced.
- Python automation shortens vulnerability triage and remediation cycles and reduces repetitive manual work.
- The SOC benefits from reliable security tooling, useful integrations and improved automation.
- Reporting provides a clear view of material exposure, remediation performance and residual risk.
- Security, Infrastructure, IT Operations and application teams share accountability for reducing security risk.
Benefits:
-
25 days annual leave (based on full-time hours) PLUS bank holidays.
-
3 FI Days per year.
-
Hybrid working available, equipment provided for homeworking.
-
Flexible-working positive employer with a range of family-friendly policies
-
Employee Assistance Programme: 24-hour confidential access to counselling and support services
-
Competitive Pension
-
Private Medical Insurance
-
Training and development opportunities
-
Long term career prospects in a growing company
-
Employee perks including a range of discounts to suit your lifestyle.
First Intuition are dedicated to safeguarding children, young people, and vulnerable adults. All roles require reference checks, an enhanced DBS, and online searches in line with KCSIE guidelines. This post is exempt from the rehabilitation of Offenders Act 1974.
First Intuition is committed to safeguarding and promoting the welfare of children and vulnerable adults. All staff are expected to share this commitment and adhere to our Safeguarding and Prevent Policy, which can be viewed here.
We are a disability confident employer, committed to equal opportunities for all applicants. If you need reasonable adjustments during the recruitment process, please let us know