Principal Security Engineer — Security Engineering Solutions
Role Overview
We are seeking a Principal Security Engineer to provide hands-on technical leadership across network and infrastructure security engineering, architecture, automation and operational security.
Contract: 6 Months (Renewable), with potential for long-term extension
IR35: Outside IR35
On-site: 2–3 days per week in Greater London during the first month, reducing to 1–2 days per week thereafter
Key Responsibilities
• Lead security engineering, architecture, implementation and operational maturity across enterprise environments.
• Design and manage WAF, DDoS, NDR and micro-segmentation solutions.
• Own and optimise Imperva WAF & DDoS, ExtraHop NDR and Illumio micro-segmentation.
• Drive security automation, Security-as-Code, Infrastructure-as-Code and API-driven configuration management.
• Integrate security platforms with SIEM, SOAR, ITSM, monitoring and telemetry.
• Provide technical leadership for complex security incidents, troubleshooting and root-cause analysis.
• Define security architecture, engineering standards and reusable security patterns.
• Partner with Network, Infrastructure, Software Engineering, SOC and Application teams.
• Mentor security engineers and act as an escalation point for complex technical issues.
Essential Skills & Experience
• Strong hands-on enterprise security engineering experience.
• Expertise in several areas including WAF, DDoS, NDR, micro-segmentation, network security architecture, TCP/IP, security monitoring, cloud/hybrid security and incident response.
• Hands-on experience with Imperva, ExtraHop and/or Illumio highly desirable.
• Strong networking knowledge: TCP/IP, DNS, HTTP/HTTPS, TLS, routing, firewalls, ACLs, load balancing and network segmentation.
• Experience with Python, PowerShell, REST APIs, JSON/YAML, Git, Terraform/IaC, CI/CD and security automation.
• Proven Principal/Lead-level technical leadership, problem-solving and stakeholder engagement skills.
Desirable
• Financial services or other regulated-industry experience.
• AWS/Azure, hybrid cloud, Zero Trust and DevSecOps experience.
• SIEM/SOAR/ITSM integrations.
• Security architecture reviews and major cyber incident experience.
• Relevant security, networking, cloud or vendor certifications.