Help us use technology to make a big green dent in the universe. It's a really exciting time in energy. Help us make a real impact on shaping a better, more sustainable future.
We are very excited to be building a small and efficient Cyber and Information Security team at Octopus Energy Group.
We're hiring for both Mid-Level and Senior Security Engineers. We are looking for ambitious, knowledgeable, and experienced Security Engineers to join our team, to grow with the rest of the company, and ensure we continue to do so in a secure and safe way.
You will be a key partner in defining what Security is at Octopus Energy Group. We will be shaping this team to provide a world class support service to our employees, building our way out of problems with engineering firepower and undertaking transformational organisational change.
You'll play a crucial role in helping to secure our software development processes, securing our platform services, integrating security practices, and shaping a culture of security. This is a creative, and collaborative position that is a full-time member of a Cloud-First organisation. If you're passionate about Cloud technologies and driving security by design, we encourage you to apply.
Specifically, we're looking for Security Engineers with at least 2 years of relevant experience to help us improve security across the Octopus Energy Group. Senior Security Engineers should bring 4+ years of relevant experience.
What you'll do:
- Build and maintain security tooling and infrastructure to improve our overall security posture
- Respond to security incidents and help improve incident processes
- Work with the wider Platform and application teams to ensure that our infrastructure, systems, and applications are secure
- Develop secure coding practices and provide guidance to development teams on application security best practices
- Keep up to date with the latest security trends and technologies related to application security, and evaluate their potential impact on our systems and data
- Develop and maintain security documentation related to application security, including policies, procedures, and guidelines
This is a varied role in a growing team. You'll have the opportunity to get involved in other security-related projects and initiatives as needed. We encourage you to take on new challenges that align with your skills and interests, and to collaborate with other teams to drive improvements in security across our entire organisation.
What you'll have:
- Excellent security and technology background
- Strong understanding of web application security concepts, including OWASP Top 10 vulnerabilities, secure coding practices, and application security testing tools
- Experience with security tools and technologies, such as web application firewalls (WAFs), and static and dynamic application security testing (SAST/DAST) tools
- Experience in endpoint (e.g., EDR and ZTNA) and cloud (e.g., CSPM and CNAPP) security tooling
- Experience with security SaaS solutions
- Good AWS experience (or knowledge) and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS)
- Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks
A good candidate will have experience in at least some of the areas mentioned; we're not expecting any candidate to be an expert in all areas.
What will help:
- Security certifications (any of the well-known abbreviations)
- Certifications from cloud providers' certification paths
- Security qualifications (e.g., apprenticeships or degrees)
- Experience with preparing high-quality documentation
- Experience using logging tools (whether this was a SIEM system or not) to generate alerts and reports
- Knowledge of the MITRE ATT&CK framework
Why else you'll love it here
- Wondering what the salary for this role is? Just ask us. On a call with one of our recruiters, it's something we always cover as we genuinely want to match your experience with the correct salary. We don't advertise because we have a degree of flexibility and want to find the right fit for you.
- Octopus Energy Group has a unique culture. An organisation where people learn, decide, and build quicker. Where people work with autonomy, alongside a wide range of amazing co-owners, on projects that break new ground. We want your hard work to be rewarded with perks you actually care about. We were recently named the UK's top company to work for , and we ranked in the top ten in the Sunday Times Best Places to Work 2024 . Our Group CEO, Greg, has recorded a podcast about our culture and how we empower our people. We've also been placed in the top 10 companies for senior leadership .
- Visit our UK perks hub - Octopus Employee Benefits
Our process usually takes up to 4 weeks, but we'll always do our best to flex around what works for you. Along the way, you'll chat with our recruitment team, and your Recruiter will help you throughout different stages. Got any questions? Drop us a message at and we'd love to help.
If this sounds like you, then we'd love to hear from you.
Are you ready for a career with us? We want to ensure you have all the tools and environment you need to unleash your potential. Need any specific accommodations? Let us know, and we'll do what we can to customise your interview process for comfort and maximum magic.
Studies show that some groups, like women, are less likely to apply unless they meet 100% of the requirements. If you like one of our jobs, we encourage you to apply-you might just be the candidate we hire. We value honesty, empathy, and diverse perspectives. We are an equal opportunity employer and do not discriminate based on protected attributes. Our commitment is to provide equal opportunities, an inclusive work environment, and fairness for everyone.