Security Engineer
About this role
By partnering with us, clients future-proof their operations, unlock actionable insights, and stay ahead of the curve in a rapidly evolving world.About the RoleWe are looking for a hands-on Security Engineer to strengthen our security operations and take ownership of key risks and controls. This is the first dedicated security hire in the team and will play a central role in improving monitoring, detection, data protection, and automation across the organisation. This is an internal role focused on securing our own IT systems and infrastructure.You will combine technical security engineering with practical compliance ownership, ensuring that our ISO 27001 and UK Cyber Essentials controls are not just documented, but effective and measurable.As our first dedicated security engineer, you will help shape how security operates day to day. The scope is broad by design, but success in this role is not about doing everything at once. It is about understanding risk, making sound technical judgments, and prioritising the work that meaningfully reduces risk for the business.We value pragmatism over perfection. You will be expected to identify gaps, propose improvements, and execute in a structured, risk-based way, focusing on impact rather than activity.This role is ideal for someone who enjoys building, automating, and improving systems while taking real ownership and influencing how security evolves as the company grows.Our EnvironmentWe operate a cloud-first infrastructure of approximately 300 employees with Apple endpoints and minimal reliance on Microsoft technologies. Security controls are primarily implemented across SaaS platforms and cloud services, with a strong focus on automation and API-driven workflows.Core stack: Okta, Google Cloud, Datadog, Island Enterprise Platform, Jamf, VantaKey ResponsibilitiesImprove and tune SIEM detection rules and alerting workflowsIdentify gaps in detection coverage and develop pragmatic detection improvements based on evolving risks and changes in our environmentEnhance DLP and secure web gateway controlsMonitor and remediate findings from CASB and ISPM platformsInvestigate security alerts and incidents, including root cause analysisSupport vulnerability management across cloud, endpoints, and SaaS platforms, including prioritisation and remediation trackingMaintain and improve incident response procedures, including playbooks, tabletop exercises, and post-incident reviewsProvide security input into internal enterprise technology decisions, including new SaaS integrations and cloud architecture changesAutomate repetitive security workflows and reportingReduce false positives and continuously improve signal qualityAutomation and AI EnablementUse scripting and automation to streamline security operationsLeverage AI tools responsibly to improve investigation workflows, reporting, and documentationIdentify opportunities where AI can improve efficiency without increasing riskBuild lightweight automation to reduce manual compliance overheadCompliance and Control EngineeringOwn and maintain selected compliance controls (ISO 27001)Ensure controls are technically implemented and operating effectivelyMaintain evidence and support internal and external auditsTrack and remediate control gapsGovernance and Risk SupportSupport risk assessments and control reviewsContribute to improving security policies and standardsSupport access reviews and vendor security assessmentsCommunicate technical risk clearly to non-technical stakeholdersWhat We’re Looking For5–7 years of hands-on experience in information securityPractical experience operating and tuning security tools such as ISPM, SIEM, DLP, CASB, EDR, and related platformsSolid understanding and real-world implementation experience of Zero Trust principles, including identity-based access controls, least privilege, device posture enforcement, and continuous verificationExperience in incident response and security investigationsStrong understanding of cloud logging, telemetry pipelines, and log source integrationStrong technical mindset with automation experience (Python, Bash, or similar scripting languages) to streamline security operations and reduce manual effortExperience supporting ISO 27001 or similar compliance frameworks, including control ownership and audit readinessComfortable taking ownership of security controls, identifying gaps, and driving measurable improvements independentlyFull professional fluency in English, with the ability to communicate clearly with technical and non-technical stakeholdersNice to HaveExperience in cloud environments, especially Google CloudExperience with Infrastructure as Code such as Terraform or PulumiExperience preparing for or supporting ISO auditsRelevant certifications (CompTIA Security+, Google Professional Cloud Security Engineer, or similar)Benefits we offer include:27 days of vacationSupplementary and additional health insurance50% covered MultiSport membershipHybrid working model for flexibility and balanceWhy Datatonic?Join us to work alongside AI enthusiasts and data experts who are shaping tomorrow. At Datatonic, innovation isn’t just encouraged - it’s embedded in everything we do. If you’re ready to inspire change and deliver value at the forefront of data and AI, we’d love to hear from you!Are you ready to make an impact?Apply now and take your career to the next level.
What this role is, and what else it is called
Employers in the UK advertise this kind of work as Fire & Security Engineer, Cybersecurity Engineer, Cyber Security Consultant and Cyber Security Engineer too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in the UK, advertised as hybrid, splitting time between home and the office.
How this role compares to the market
1,968 live UK roles list Python right now, from 583 employers. The median advertised salary is £80,000; 30% are advertised as remote. Browse Python roles.
542 live UK roles list Google Cloud right now, from 224 employers. The median advertised salary is £90,000; 30% are advertised as remote. Browse Google Cloud roles.
Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.
Technologies mentioned
Detected on Datatonic's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site.