Information Security Engineer
London
Job description
Are you an Information Security enthusiast?
Zempler Bank are proud to be looking for an experienced Information Security Engineer on a Full Time & Permanent basis.
Who we are
First established in 2004, Zempler Bank are here to make money simpler. We are a “Top 100 Best Companies” employer and ranked as a leading FinTech bank from independent national survey results, conducted by CMA (Competition & Markets Authority) in 2024, as the only UK bank to rank in a top five across all three categories within business banking.
Our mission statement, which underpins everything we do, is to provide the UK’s underserved businesses with easy to access and simple to use banking services that helps them succeed.
The Role
This Information Security Engineer job is a technical focused role (with aspects of compliance) responsible for supporting and improving the Information Security control framework used by us at Zempler Bank.
Furthermore, the Information Security Engineer will operate in a business that offers a flexible working culture/approach, with independence and scope to fundamentally positively impact how IT Security is implemented in a regulated banking environment.
Team Hybrid Working Style
We are very proud to offer one of the most flexible hybrid working arrangements within the Financial Services/Banking industry! The expectation for this role will require a minimum of one day each month working out of our London Bridge HQ.
Key Accountabilities Include
Security Control Framework:
- Ensure high levels of information security are maintained across Zempler Bank and assist other technical teams to understand and meet those high levels based upon PCI-DSS compliance and NIST-CSF
Lifecycle Support:
- Support management of Information Security assets to ensure they are secure and fully supported, including Patch and Vulnerability management to agreed standards
Incident Response:
- Configure and respond to monitoring alerts for issues detected by Information security tools, supporting incidents 24x7 (average once per month) as required, escalating when required
- Support the Post Incident Resolution (PIR) process and provide recommendations to avoid future incidents
Documentation:
- Maintain documentation and configuration repositories, including security diagrams, IT asset management systems and agreed documentation
- Document and share knowledge with other members of the team, including delivering training sessions when required
Change Management:
- Support the wider project and change programme, design and deliver agreed improvements following governance processes and industry best practices including documentation
- Ensure all changes are released or made into controlled environments following agreed and repeatable processes, including roll-back to a known working state
Reporting:
- Provide agreed reporting and updates to the Chief Information Security Officer and wider team, including accurate status of tickets being worked on
Threat and Risk Management:
- Risk mitigation through best practice and by following company procedures
- Identify risks and escalate to management, maintain the Information Security risk register and support the wider Enterprise Risk Management framework
- Use horizon scanning to keep abreast of relevant new technologies, security threats and regulatory changes
Personal Development Plan (PDP):
- Agree a PDP and objectives with your line manager and track progress to agreed timescales
You’ll Need To Have
Essential:
- Established experience of working within an Information Security team within a similar engineering position
- Experience and familiarity with one or more of the following security tools: Logrythm SIEM, McAfee suite, Firewalls, Officer 365 Compliance tools, CASB
- Experience and ability to achieve and maintain PCI, or similar security standards (e.g. NIST-CSF, ISO 27001)
- Experience in Windows Server, security configuration: Windows 2012, 2016; Active Directory; Group Policy, Certificate Services;
- Office 365 and Windows 10 security configuration
- Automation through scripting and other tools
- General security technical skills: networks, storage area networks, backups, firewalls, virtualisation, virtual desktop environments, monitoring, alerting, efficiency and optimisation, documentation, procedural controls, identity and access management, automation, 24x7 support
- Good verbal, written communication and interpersonal skills
Desirable:
- Experience with CentOS/RHE, Kali Linux, Penetration Testing, Red Teaming.
- Ideally CISSP, MCSE and ITIL qualified
- Experience working in financial services, payment organisations, Banks or an understanding of working in a regulatory environment where good governance is a requirement and a benefit
- Membership of relevant professional body
- Strong understanding of open data sources and supporting the delivery of APIs, e.g. for open banking
In Return You’ll Enjoy
· Competitive basic salary
· Additional benefit allowance representing 7.5% of your annual salary allowing you the flexibility to decide your own benefits (or simply absorb this into your monthly income).
· 26 days’ holiday increasing each year of service to 33 days
· Ability to buy and sell a further 5 days holiday each year
· 4 x Life Assurance
· Pension salary sacrifice
· Option for LinkedIn Learning license
· Family friendly policies
· Regular social activities and team events
· Charity Volunteering Day
· Free drinks and snacks in the office
Zempler Bank is an equal opportunity employer. Individuals seeking employment are considered without regard to race, religion, national origin, age, sex, gender, gender identity, gender expression, sexual orientation, marital status, medical condition, ancestry, physical or mental disability, military or veteran status, or any other characteristic protected by applicable law.
- Job type
- Permanent
- Industry
- MIS / IT
- Posted
- 2025-03-14T00:00:00