More jobs:
Security Test Engineer
Job in
Cumbernauld, North Lanarkshire, G67, Scotland, UK
Listed on 2025-12-23
Listing for:
McNally Recruitment Ltd
Full Time
position Listed on 2025-12-23
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
The Security Test Engineer will be responsible for ensuring the security robustness of software and firmware components within our product portfolio. This role involves conducting threat modeling, security testing, and vulnerability assessments, while ensuring compliance with internal processes and industry standards. The ideal candidate will be passionate about cybersecurity, detail-oriented, and experienced in testing within industrial environments.
PLEASE NOTE
theclientwillonlyacceptcandidateswhoareauthorisedtoworkinthe
UK,
without
the
requirementforsponsorshiporANYtypeofvisa
(e.g.dependant/spousal,post-studyetc.).
In addition,thisrole
hybridbasedwith4daysintheScottishoffice
,therefore
youshouldcurrentlybelocatedin
Scotland.
- Perform security requirements analysis and threat modeling.
- Conduct risk analysis and define test strategies aligned with security objectives.
- Plan, execute, and report on security testing activities, including:
- Tool and technique selection
- Security requirements testing
- Threat mitigation testing
- Vulnerability testing
- Abuse case testing
- Attack surface analysis
- Regression testing
- Test automation
- Analyze, report, and track security defects.
- Ensure compliance with internal processes and applicable standards (e.g. IEC 62443, ISO 27001).
- Support internal and external audits as required.
- Drive continuous improvement by staying updated on emerging threats, tools, and best practices.
- Occasional travel may be required, such as training or customer support.
- Minimum 5 years of experience in software and/or firmware testing
- Engineering degree in Software, Computer Science, Cybersecurity or equivalent demonstrated knowledge.
- Proficiency with tools such as Burp Suite, OWASP ZAP, Nessus, Metasploit, Wireshark, Nmap, Fortify, Checkmarx.
- Knowledge of scripting languages such as Python, JavaScript, Bash, or Power Shell.
- Understanding of encryption algorithms, key management, and secure protocols (TLS, SSH, etc.).
- Strong understanding of common vulnerabilities (e.g., OWASP Top 10, CWE/SANS Top 25).
- Familiarity with Linux, Windows, and network protocols (TCP/IP, DNS, HTTP/S).
- Understanding of industrial protocols (e.g., Serial, Modbus, HART).
- Knowledge of industry standards: IEC 62443, ISO 27001, NIST, OWASP.
- Experience implementing Dev Sec Ops best practices;
Azure Dev Ops experience is a plus. - Self-directed and motivated in a team oriented environment.
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×