Cyber Security Network Engineer
About this role
Job Title: Cyber Security Network Engineer Department: IT Reports to: Head of IT Controlled Function: N/A Location: London Hours of work: Full-time, Monday to Friday the role is based 4 days in the office and 1 day working from home Job Purpose: We are seeking a motivated, hands-on and experienced Cyber Security Network Engineer with experience in the banking industry ideally with Oracle Flexcube and Oracle Banking Digital Experience (OBDX). This role is to own the bank’s technical security posture, protect systems from cyber threats, and manage perimeter and application security platforms. This role bridges the gap between infrastructure engineering and threat management, ensuring high availability, robust defence-in-depth, and strict regulatory compliance across all banking networks. Main Responsibilities: Vulnerability Management Scanning & Triage: Run regular vulnerability scans across networks applications, and endpoints; triage findings based on business risk and CVSS scores and coordinate rapid remediation with IT operations teams KPI Reporting: Track, analyse, and report on vulnerability lifecycle metrics and KPIs for senior leadership and regulatory oversight bodies. Patch Verification: Validate the effectiveness of deployed patches and configuration changes via targeted follow-up scans. Security Infrastructure Ownership Next-Generation Firewalls (NGFW): Manage and maintain Cisco Firepower firewalls, including complex rule set architecture, IPS/IDS signature tuning, URL filtering, and malware protection policies. Web Application Firewalls (WAF): Administer F5 WAF (Advanced WAF / ASM) to protect online banking portals, API endpoints, and mobile banking backends against OWASP Top 10, credential stuffing, and advanced bot attacks. Application Delivery Controllers (ADC): Manage Citrix ADC / NetScaler load balancers, ensuring secure traffic distribution, robust TLS/SSL cipher suite configuration, and secure session management. Zero Trust & Access Control: Maintain secure Remote Access VPNs, site-to-site IPsec tunnels, and network access control (NAC) policies to enforce micro-segmentation. Threat Detection & Response SIEM Monitoring: Monitor, analyse, and triage alerts from the Security Information and Event Management (SIEM) platform, acting as a technical escalation point for the SOC. Use Case Development: Develop, test, and tune custom detection use cases, correlation rules, and alert logic to improve detection quality and reduce false positives. Incident Response: Support incident response phases (containment, eradication, recovery) during active network-level cyber security incidents. Security Hardening & Architecture Baseline Configurations: Establish, update, and enforce secure configuration baselines (e.g., CIS Benchmarks) for Windows servers, Linux/Unix environments, and core network devices. Network Segmentation: Design and audit zone-based network segmentation to isolate critical banking environments (e.g., SWIFT, card processing, core banking) from untrusted networks. Change Management Governance & Discipline Structured Planning: Author comprehensive change requests detailing exact technical steps, complete documentation, precise impact assessments, and zero-downtime execution windows. Rigorous Testing: Mandate and execute thorough pre-implementation testing in non-production environments to validate security policies, rules, and configurations before live deployment. Fail-Safe Rollbacks: Design, document, and test explicit, step-by-step rollback procedures for every infrastructure change to guarantee immediate service restoration in the event of failure. Peer Review: Lead and participate in peer-review cycles for complex network and security modifications to maintain institutional standards and eliminate single points of failure. Project Security & Compliance Risk Reviews: Perform technical security reviews and threat modelling for new infrastructure projects, cloud migrations, and standard change requests. Penetration Testing: Coordinate annual penetration testing cycles with external vendors, validate findings, and track the remediation of identified flaws. Regulatory Alignment: Ensure all network security controls comply with industry standards and best practice. Experience & Skills required: Required Experience 5+ years of experience in network engineering with a heavy focus on cyber security, ideally within a regulated financial institution or enterprise environment. Proven hands-on experience configuring and troubleshooting Cisco Firepower, F5 ASM/WAF, and Citrix NetScaler. Strong understanding of core networking protocols (BGP, OSPF, EIGRP), the TCP/IP stack, and advanced cryptographic protocols (TLS 1.3, SSH, IPsec). Desired Certifications (One or more) General Security: CISSP, CISM, or CEH. Network / Vendor Specific: CCNP Security, Cisco Certified Specialist – Network Security Firepower, F5-CA/F5-CTS, or Citrix Certified Professional – Networking (CCP-N). Soft Skills Strong collaborative skills to work effectively alongside standard IT Infrastructure and DevOps teams. Excellent technical writing skills for creating clear, compliant security documentation and architecture diagrams. Applicants must have the right to work in the UK. Proof of eligibility will be required as part of the hiring process. Apply now Send your cover letter and CV to recruitment@nbeuk.com with "Vacancy 011 Application" and your full name in the subject.
What this role is, and what else it is called
Employers in London advertise this kind of work as Security Engineer, Fire & Security Engineer, IT Security Analyst and Cyber Security Consultant too, so it is worth searching more than one wording. It is a mid-level Cybersecurity role in London, advertised as fully remote, so it is open to candidates working from home.
About hiring at Nbeuk
Nbeuk has 5 other live technology roles on its careers page, across IT Analysis & Consulting, Cybersecurity and DevOps, Platform & SRE. Of those, 17% are advertised as fully remote and 0% as hybrid. Elsewhere in its adverts Nbeuk asks for Jira, SQL, Oracle and Microsoft SQL Server. See all Nbeuk roles, salaries and stack.
How this role compares to the market
610 live UK roles list Linux right now, from 231 employers. The median advertised salary is £65,000; 24% are advertised as remote. Browse Linux roles.
237 live UK roles list Cisco right now, from 73 employers. The median advertised salary is £40,000; 19% are advertised as remote. Browse Cisco roles.
London has 4,312 live IT vacancies across 1,365 employers, with a median advertised salary of £70,000. Browse London roles.
Market figures are today's snapshot of live UK roles on employer careers pages; see hiring trends.
Technologies mentioned
Detected on Nbeuk's careers page. ProdReady Recruitment lists this vacancy as an aggregator and is not the employer; applications go to the employer's own site. More IT jobs in London.