CV-Library
Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
At CV-Library, we have a simple vision: to help the world to work and we are looking for exceptional and talented people to help us realise this vision in both UK and overseas markets.
We are in a period of focused internal investment, following a year of key strategic acquisitions and significant investment across all parts of the business, from Tech and Data to People and HR, there's never been a more exciting time to join us or a better place to grow your career!
The Role
Hours: Monday-Friday, 9:00-17:30
Location: Fleet
Working Pattern: Hybrid - 3 days a week on site
This is a security role built for someone who wants to own the threat, not just log it. As Security Engineer, you'll be the person who understands what's actually at risk across a modern Cloud native microservice platform and our internal IT estate, from SIEM alerts to Microsoft 365 endpoint security, and who sets the priorities that matter. You won't be buried in compliance paperwork. You'll direct a capable Platform Ops team on remediation while you stay focused on the threat picture, the tooling and the DevSecOps thinking that keeps CV-Library ahead of it.
You'll report directly to the Platform & Service Operations Manager, with a genuine mandate to shape how security is done, not just document it. Compliance still matters, and you'll keep ISO 27001 documentation and audit evidence in good shape as you go, but it's the by-product of doing security well, not the job itself.
Responsibilities:
- Own the day-to-day management of security alerts, investigations and incidents across CV-Library's technology estate
- Monitor emerging cyber threats and threat intelligence, assessing potential risks and recommending improvements to security controls
- Lead the initial response to security incidents, coordinating containment and remediation activities with relevant technical teams
- Maintain incident records, conduct post-incident reviews and ensure lessons are learned are embedded into processes, tooling and controls
- Manage and continuously improve the organisation's security tooling, including SIEM, endpoint protection, vulnerability management and cloud security solutions
- Take ownership of endpoint and Microsoft 365 security, including device security, conditional access policies and identity protection controls
- Define and maintain security standards and guardrails for cloud infrastructure and software delivery, working closely with Platform DevOps teams
- Manage identity and access management processes, supporting user provisioning, access reviews and least-privilege principles
- Act as the security subject matter expert, providing guidance on infrastructure, platform and application changes
- Oversee the vulnerability management lifecycle, ensuring security weaknesses are identified, prioritised and remediated effectively
- Coordinate external penetration testing activities and track remediation actions through to completion
- Maintain security documentation, policies and audit evidence, supporting ongoing ISO 27001 compliance and certification requirements
- Apply GDPR and data protection principles to ensure security controls, processes and documentation meet regulatory expectations
- Support supplier and third-party security assessments, helping to identify and manage external risks
- Assess the secure use of AI technologies across the business and champion a strong security culture by promoting best practice across best technology and non-technical teams
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What We're Looking For


Get help with your application
Your very own career expert that helps elevate your application to the next level.
- Strong technical knowledge of security tools, frameworks and best practice
- Solid understanding of cloud-native infrastructure (AWS, Kubernetes/EKS) sufficient to assess and prioritise risk and to direct Platform Ops on remediation, without owning infrastructure changes directly
- Experience with penetration testing engagement and vulnerability management processes
- Understanding of endpoint protection technologies and policy configuration, including Microsoft 365 security tooling (e.g. Defender, Intune, Conditional Access)
- Working knowledge of Identity and Access Management principles
- Strong incident response and threat intelligence skills, including SIEM-based monitoring and triage
- Familiarity with security accreditations such as ISO 27001 and what they require operationally
- Working knowledge of UK GDPR and data protection principles, particularly as they relate to security control and audit documentation
- Excellent communication skills, able to convey security matters clearly to both technical and non-technical audiences
We are actively committed to promoting a fully diverse and inclusive workforce and we welcome applications for this role from all candidates who meet the key requirements.
Please do not hesitate to get in touch should you require any reasonable adjustments to assist with your application.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Location