Our ‘black belt’ specialists are leaders in their domains: digital champions, delivery-focused experts, top-tier security professionals, AI thought leaders, and engineering best practice advocates.
With a global presence and local expertise, we deliver innovative solutions without compromising on quality. Our multidisciplinary teams provide tailored expertise to solve complex problems at scale, ensuring engineering excellence through our top technologists.
Empower Your Career with Us
Are you ready to join a dynamic team that empowers businesses through robust engineering capabilities? We seek talented individuals who thrive in a fast-paced environment with a strong sense of urgency and a focus on execution.
Overview of the Role
We are looking for two highly capable Security Configuration Management – Control Engineers to join our team.
We are on a mission to uplift our Risk and Security Posture Management and improve the security posture of our most critical assets.
In this hands-on role, you will be responsible for the design, operation, and ongoing effectiveness of the Security Configuration Management (SecCM) control across the organisation.
You will ensure technology assets are securely configured by default, continuously checked, and kept compliant with approved security baselines and regulatory requirements.
A major focus of this role involves remediating control gaps, updating vendor hardening guidelines, and operating enterprise tooling to drive practical engineering outcomes.
Key Responsibilities
-
Continuous Monitoring & Scanning: Run daily configuration scans using Qualys to identify variations from established security baselines.
-
Guidance & Remediation: Review and update existing vendor hardening guidelines, ensuring they reflect current best practices and audit requirements.
-
Tooling Integration: Improve and configure ServiceNow reporting to accurately reflect asset classes, control gaps, and remediation tracking.
-
Automation: Configure automation to determine variations in guidelines and streamline the detection of compliance gaps.
-
Risk Management: Actively identify, investigate, and resolve scanning gaps related to authentication failures, tooling limitations, CMDB discrepancies, or asset lifecycle issues.
-
Cross-Functional Collaboration: Provide technical guidance to engineering teams on remediation approaches and prioritisation to reduce the current backlog.
Skills and Experience
-
Security Tooling: Proven experience operating enterprise security tooling, specifically Qualys, Wiz, and ServiceNow SecOps / Configuration Compliance.
-
DevSecOps Experience: A strong background bridging development, operations, and security with a risk-first mindset.
-
Configuration & Hardening: Deep familiarity with secure configuration benchmarks (such as CIS) and vendor hardening guides.
-
Risk & Assurance: Experience supporting internal assurance, CIA testing, and audit activities by providing evidence, explanations, and control artefacts in a large enterprise.
-
Analytical Problem Solving: A structured approach to translating strict control requirements into practical, achievable engineering outcomes.