IT Security Engineer Apply
IT Security Engineer (Hybrid: 3 days on-site in Hertfordshire / 2 days remote) | £45–50k | PermanentSR2 is partnering with a well-established, member-owned UK organisation to hire an IT Security Engineer to strengthen cyber resilience and improve day-to-day security operations. This is a hands-on role sitting within IT, working closely with infrastructure and support teams to embed security into BAU and projects.What you’ll be doingOwn day-to-day vulnerability monitoring and remediation, including maintaining a vulnerability register and tracking actions to closureTriage, categorise and prioritise vulnerabilities based on risk, exposure and business impactSupport patching, configuration hardening and decommissioning activities to reduce risk exposureMonitor and respond to security alerts and incidents, contributing to investigation and improvement actionsHelp improve detection and response capability (more proactive monitoring and response workflows)Work with external providers (e.g., SOC / security vendors) to reduce high-priority risksDevelop and maintain security playbooks (phishing, ransomware, account compromise, etc.)Provide security input into projects, changes and supplier reviews so security is built-in from the startSupport audits / assessments (e.g., vulnerability assessments, pen tests, configuration benchmarks, PCI where relevant)Contribute to awareness initiatives and practical security guidance across the businessSupport progress against NIST CSF focus areas and maturity improvementsWhat we’re looking for3+ years in security operations / cybersecurity engineering (or strong IT ops experience with security ownership)Strong understanding of vulnerability management processes and risk-based prioritisationFamiliarity with email + endpoint security controls (e.g., Defender-style toolsets, phishing controls, email security)Awareness of IAM concepts: MFA, conditional access, privileged access/PIMComfortable working with technical teams to get remediation delivered (patching cycles, change, infrastructure support)Clear communicator who can explain risk to both technical and non-technical stakeholdersBonus points for: SIEM exposure, threat hunting, cloud security, automation/scripting, infrastructure/networkingPackage£45–50k salary rangePrivate medical insurance, life assurance, permanent health insuranceStaff discount, interest-free loan scheme, sports & social clubWorking patternHybrid: 3 days per week on-site in Hertfordshire, 2 days remoteFull-time: 37.5 hours/week

