Sword Group on cord

Sword Group

Cyber Security Engineer

External position
Aberdeen, UK
Hiring internally for Sword Group?
Consultancy · Data
Posted
6 days ago
Checked
cord regularly checks that external positions are still open
20 hours ago

Skills & Experience

Job roles: Security Engineer
Experience level: Senior
Core skills considered: APIs, Azure, Cloud Security
Other skills considered: Cyber Security, Security Testing, Threat Detection

Logistics

Base salary: Undisclosed
Some companies on cord are unable to disclose salaries publicly due to internal company policies. Message the company for salary information.
Employment type: Permanent
Remote working: Hybrid
Visa sponsorship: Not available

Job Description

We are looking for a Cyber Security Engineer to join our security team and take the lead on our security operations. Reporting to the Group CISO and working closely with IT, you will take ownership of the day-to-day running of Sword's technical security controls, with a strong focus on Microsoft security technologies. You will play a leading role in strengthening monitoring, detection, protection, and response across the business, and in automating the work that should not be done by hand. This role suits someone with at least five years of hands-on experience, a positive can-do attitude, and the ability to take ownership, work autonomously, manage workload effectively, and deliver results.

This is a hands-on technical role with real ownership, focused on implementing, operating, and improving security controls across Sword's environment. Working with IT and the wider security function, you will strengthen monitoring, protection, detection, response, and technical assurance through effective use of security technologies and services, and you will look for opportunities to automate. We are looking for someone who is proactive, practical, and delivery-focused, with the confidence to work independently, agree and manage priorities, and follow through with minimal supervision.


Key Responsibilities

  • Security Monitoring and Operations - Own the day-to-day security operations across Microsoft security technologies including Microsoft Sentinel, Microsoft Defender, Conditional Access, Entra ID, and related Azure security capabilities, strengthening monitoring, detection, protection, and response. You will help shape what effective monitoring looks like at Sword, working in partnership with the CISO and the wider IT team.
  • Vulnerability Management and Hardening - Proactive and risk-based vulnerability management, including attack surface reduction, system hardening, remediation support, and cloud security posture improvement. You will also coordinate penetration testing and security assessments, and drive the findings through to remediation.
  • Automation and Continuous Improvement - Reduce manual effort across security operations through automation, scripting, and integration. Where work is repetitive, look to automate it. Identify and implement improvements to security tooling, detection logic, control effectiveness, and operational processes through tuning, automation, and incremental engineering. This is an important part of the role.
  • Security Tooling and Services - Own the security tooling estate and work closely with our external providers to make sure the services we buy deliver the outcomes we need, resolving technical issues and improving day-to-day security outcomes.
  • Incident Investigation and Response - Own and run security incidents from start to finish, covering technical investigation and triage, containment, remediation, closure, and keeping the business informed as it unfolds. We are looking for someone who has personally led incidents rather than taken part in them as one of a wider team, and who turns each one into a lasting improvement in our detection and response.
  • Security Awareness and Enablement - Provide the technical input behind awareness activity, simulated phishing exercises, and secure working practices, helping colleagues work safely without adding friction to their day.
  • Technical Compliance and Assurance - Own the technical controls behind our certifications and assurance activity, including Cyber Essentials Plus, ISO 27001, evidence gathering, and remediation.
  • Technical Risk Assessment - Lead technical security risk assessment across projects, suppliers, and internal services, identify where we are exposed, and drive practical remediation and hardening.
  • Regulatory and Client Requirements - Implement, maintain, and evidence the technical controls we need to meet relevant legal, regulatory, and client security obligations.
  • Supplier and Integration Security - Lead technical reviews of supplier and partner services, integrations, and access arrangements, and make sure the right controls are in place and stay in place.

You will need to be able to demonstrate technical experience in cyber security engineering or security operations, including direct responsibility for the day-to-day running of security tooling and incident response. Attitude matters greatly. We are looking for someone who delivers results and brings a positive, practical approach to solving problems.

You should have hands-on experience in most of the following areas, and we may explore some of them practically during the interview process:

  • Microsoft security technologies, in depth. Microsoft Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint detection and response.
  • Automation. Practical experience of removing manual effort from security operations using scripting, playbooks, Logic Apps, APIs, or similar. You should be able to talk about something you automated, what it replaced, and what it saved.
  • Security control operation. Operating and improving security controls across areas such as endpoint protection, SIEM, vulnerability management, identity and access management, data protection, email security, cloud security posture, and system hardening.
  • Frameworks and standards. Applying security frameworks, standards, and regulatory drivers such as NIST, ISO 27001, GDPR, and NIS2 through practical technical controls.
  • Cyber Essentials Plus. Technical control implementation, evidence collection, remediation tracking, and preparation for assessment.
  • Secure deployment. Supporting the secure configuration and deployment of applications, infrastructure, identities, and cloud services, working with IT teams to embed appropriate controls without slowing delivery.
  • Communication. Comfortable at both ends of the conversation: technical enough to work directly with our security operations centre on detections and incidents, and clear enough to explain to senior stakeholders, up to and including the CEO, what has happened, what it means, and what we are doing about it. You will also provide practical guidance to colleagues and technical input to awareness, audit, and assurance activities.
  • Background. Experience gained in a complex business environment, working with internal teams and external providers, ideally including a managed service or multi-client setting.

Qualifications and Personal Skills

  • Relevant technical certifications are desirable, particularly in Microsoft security technologies such as SC-200, SC-300, SC-400, AZ-500, or similar.
  • Broader security certifications are welcomed but not essential if you can demonstrate strong hands-on technical capability.
  • Takes ownership, works independently when needed, and stays focused on delivering high-quality outcomes.
  • Curious, proactive, and comfortable working out what needs doing rather than waiting to be asked.
  • Able to manage workload effectively, prioritise sensibly, and maintain momentum in a busy technical environment.
  • Communicates clearly and works well with technical and non-technical colleagues to turn security requirements into practical actions and improvements.
  • Makes good use of tooling and automation to get more done, and is always looking for a better way to handle routine work.
  • Keeps pace with the threat landscape out of habit rather than obligation, forms a view on what new threats and techniques mean for an organisation like ours, and raises them proactively.

Company Benefits

  • competitive salary
  • pension
  • private healthcare
  • employee assistance programme
Cyber Security Engineer at Sword Group
Position posted 6 days ago

Talk directly
to who's hiring

cord intros you to the companies worth joining, from seed to enterprise.

Everything you need to find work

Surface every relevant position, direct message the people hiring and manage all your applications in one place.

Get started

Every position in one place

We index the web for open positions that might be relevant to you and bring them all in one place.

Positions you might like split into tabs based on their type

Direct messaging

No more CV blackholes. Message people hiring directly and see their activity live on cord.

A sent message to a hiring manager
A board of positions in different stages

Application management

Manage all your applications and interviews in one place.

Advanced insights

Know your worth and see how you compare with other applicants.

Visualisation of a profile match score for a position and score comparison with other applicants

Direct.
Transparent.
Human.

On cord you can message people hiring directly, see when they were last active, how responsive they are and access transparent information that you wouldn't be able to find anywhere else.

Photos people at Starling BankPhotos people at Starling BankPhotos people at Starling BankPhotos people at Starling BankPhotos people at Starling Bank
Starling Bank on cord

Starling Bank

Full Stack Engineer (ML Ops)

London, UK
FinTech · Banking · Finance
A better bank for everyone
Active
over 6 months ago
Responds to
0% of requests
Responds in
1h 55m
Requests
7 pending

Skills & Experience

Job roles: Full Stack
Experience level: Mid, Senior
Core skills considered: Java, React, Redux, AWS, JavaScript

Logistics

Base salary: £70K - £110K
Employment type: Permanent
Remote working: Hybrid (up to 2 remote days p/w)
Visa sponsorship: Not available

Job Description

Starling is the UK’s first and leading digital bank on a mission to fix banking! Our vision is fast technology, fair service, and honest values. All at the tap of a phone, all the time.

Starling is the UK’s first and leading digital bank on a mission to fix banking! We built a new kind of bank because we knew technology had the power to help people save, spend and manage their money in a new and transformative way.

We’re a fully licensed UK bank with the culture and spirit of a fast-moving, disruptive tech company. We’re a bank, but better: fairer, easier to use and designed to demystify money for everyone. We employ more than 3,000 people across our London, Southampton, Cardiff and Manchester offices.

Our technologists are at the very heart of Starling and enjoy working in a fast-paced environment that is all about building things, creating new stuff, and disruptive technology that keeps us on the cutting edge of fintech. We operate a flat structure to empower you to make decisions regardless of what your primary responsibilities may be, innovation and collaboration will be at the core of everything you do. Help is never far away in our open culture, you will find support in your team and from across the business, we are in this together!

The way to thrive and shine within Starling is to be a self-driven individual and be able to take full ownership of everything around you: From building things, designing, discovering, to sharing knowledge with your colleagues and making sure all processes are efficient and productive to deliver the best possible results for our customers. Our purpose is underpinned by five Starling values: Listen, Keep It Simple, Do The Right Thing, Own It, and Aim For Greatness.

Hybrid Working

We have a Hybrid approach to working here at Starling - our preference is that you're located within a commutable distance of one of our offices so that we're able to interact and collaborate in person. We don't like to mandate how much you visit the office and work from home, that's to be agreed upon between you and your manager.

Our Data Environment

Our Data teams are excited about the value of data within the business, powers our product decisions to improve things for our customers and enhance effective and agile decision making, regardless of what their primary tech stack may be. Hear from the team in our latest blogs or our case studies with Women in Tech.

We are looking for talented data professionals at all levels to join the team. We value people being engaged and caring about customers, caring about the code they write and the contribution they make to Starling. People with a broad ability to apply themselves to a multitude of problems and challenges, who can work across teams do great things here at Starling, to continue changing banking for good.

Requirements

We have built our entire banking platform in house and mostly in Java. We are looking for people who want to work on building the tooling that is used by our engineers on a daily basis.

We are looking for people who are truly full stack, and are as comfortable polishing their javascript front end as they are debugging the innards of their java applications database interactions, or standing up infrastructure with terraform. We are looking for people who can:

  • Design REST apis.
  • Code backend services, ideally using Java, or another other server side compiled language.
  • Develop modern front ends, ideally using React and Redux.
  • Get their code into the cloud and support it there, ideally on AWS.
  • Believe in clean coding, simple solutions, automated testing and continuous deployment.
  • Like to take ownership of a feature from the original idea through to live.
  • Think (like us) that a small number of empowered developers is the right way to deliver software.

Company Benefits

  • 33 days holiday (including flexible bank holidays)
  • An extra day’s holiday for your birthday
  • 16 hours paid volunteering time a year
  • Part-time and/or flexible hours available for most roles
  • Salary sacrifice, company enhanced pension scheme
  • Life insurance at 4x your salary
  • Hybrid/remote working
  • Private Medical Insurance with VitalityHealth including mental health support and cancer care. Partner benefits include discounts with Waitrose, Mr&Mrs Smith and Peloton
  • Generous family-friendly policies
  • Varied social groups set up and run by our employees
  • Perkbox membership giving access to retail discounts, a wellness platform for physical and mental health, and weekly free and boosted perks
  • Access to initiatives like Cycle to Work, Salary Sacrificed Gym partnerships and Electric Vehicle (EV) leasing

Full details are available on our careers site

Interview Process

Interviewing is a two way process and we want you to have the time and opportunity to get to know us, as much as we are getting to know you! Our interviews are conversational and we want to get the best from you, so come with questions and be curious. In general you can expect the below, following a chat with one of our Talent Team:

  • Stage 1 - 30 mins with one of the team
  • Stage 2 - Take home challenge
  • Stage 3 - 90 mins technical interview with two team members
  • Stage 3 - 45 min final with an executive and a member of the people team
Alex Yeates on cord
Message Alex Yeates at Starling Bank
Typically responds in an hour

What people are saying

2,000+

users joining every week

Oliver on cord

Oliver

Software Engineering Consultant
It's really easy to use, has a solid selection of jobs, and makes it helpful to direct message companies. The platform seems to offer a good range of opportunities while keeping the process simple and convenient.
November, 2025
David on cord

David

Lead Software Engineer
The platform allows you to create a professional CV, making the setup process simple and polished. The internal chat also provides an easy way to directly contact hiring companies, which makes communication much more efficient.
November, 2025
40,000+

open positions

Nicolae on cord

Nicolae

Senior Full Stack Developer
It is a great platform if you are looking for a job. It makes the search process straight forward and gives you access to solid opportunities.
November, 2025
3 million+

messages exchanged so far

Nicolae on cord

Nicolae

Senior Full Stack Developer
It is a great platform if you are looking for a job. It makes the search process straight forward and gives you access to solid opportunities.
November, 2025
79.05%

response rate from companies

Aarambha on cord

Aarambha

Associate Software Engineer
Absolutely amazing idea, the ability to see which recruiters are active makes finding opportunities very quick. There is a form of transparency built into the website that lacks in any other job searching platform.
August, 2025
Adam on cord

Adam

Senior Engineer
cord was great. Clean UI, easy to browse, and the data feature made it a breeze to quickly check whether my profile would match up well with a particular role. The messaging system made it easy to approach companies but also filter out unwanted requests.
August, 2025
4.6

score on Trustpilot

Talk directly to the people that matter

Join the hundred of thousands of people using cord to find work

Get started
 on cord
 on cord
 on cord
 on cord
 on cord
+418 joined last week
Moved to your Not right positions