First Intuition
Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Security Engineer
Location: Hybrid - primarily remote, with travel to FI centres as required
Contract Type: Permanent, Full-Time
About Us
First Intuition (FI) is a fast-growing, innovative accountancy training provider committed to delivering outstanding learning experiences. At FI, our commitment to excellence is driven by our core driving principle of putting people first. We take pride in nurturing talent, fostering growth, and providing unparalleled support to our students, clients, and team members, ensuring they can thrive personally and professionally.
Our success is due to our approach to training and our links with businesses. We work closely with organisations to precisely understand their needs and incorporate these into innovative course designs, where the interaction with students is tailored, personal and reflects their specific circumstances. This approach has led to First Intuition being awarded an ‘Outstanding’ rating by Ofsted.
We are seeking a hands-on Security Engineer with a strong vulnerability management focus to help reduce organisational cyber risk through effective vulnerability management, security automation and continuous improvement of security controls. This is an excellent opportunity to join a growing security function and play a key role in protecting our rapidly expanding organisation.
You will manage the technical vulnerability lifecycle from identification and validation through risk-based prioritisation, remediation and verification. You will also support security operations by improving the tooling, integrations and automated processes used by the SOC to identify and respond to security threats.
This role suits an engineer who enjoys turning security findings into measurable risk reduction, automating repeatable security processes and working across Security, Infrastructure, IT Operations and application teams.
What You’ll Do
- Operate and continuously improve the end-to-end vulnerability management lifecycle across endpoints, servers, networks, cloud services and applications.
- Run and review authenticated vulnerability assessments using Qualys, validate findings and reduce false positives.
- Prioritise vulnerabilities using exploitability, threat intelligence, internet exposure, asset criticality, business impact and technical severity rather than relying on CVSS alone.
- Translate findings into clear remediation plans with defined owners, target dates and verification criteria.
- Work with system and application owners to remediate vulnerabilities through patching, configuration changes, hardening, upgrades or compensating controls.
- Develop security automation, preferably using Python, to improve vulnerability triage, remediation workflows, data enrichment and fix validation.
- Test, coordinate and validate security patches and configuration changes while balancing security risk and operational impact.
- Support the SOC from an engineering perspective by improving security tooling, integrations, alert enrichment and automated response processes.
- Assist with security investigations where vulnerabilities, insecure configurations or missing patches may have contributed to an event.
- Use threat intelligence to provide context for vulnerability prioritisation, security alerts and emerging threats.
- Apply Zero Trust principles when implementing or improving endpoint, identity, network and cloud security controls.
- Review network-device configurations and firewall rule sets using Nipper Studio or comparable security auditing tools.
- Track vulnerabilities, exceptions and remediation progress through to verified closure.
- Produce security metrics and dashboards covering exposure, vulnerability ageing, remediation performance and residual risk.
- Maintain technical documentation, remediation playbooks and security automation code.
- Carry out tasks as delegated by the Information Systems Security Manager from time to time.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
What You’ll Bring
Essential
- Two to three years’ experience in cyber security, security engineering, infrastructure engineering, IT operations or a related technical role.
- Hands-on experience with vulnerability scanning, assessment and remediation using Qualys or a comparable enterprise platform.
- Demonstrable ability to analyse, validate and prioritise vulnerabilities using technical and business risk factors.
- Practical experience driving remediation across Windows, Linux, endpoints, networks, cloud services or applications.
- Scripting capability for security automation. Either Python or PowerShell is strongly preferred, particularly for automating vulnerability identification, triage, remediation and validation procedures.
- An understanding of CVEs, CVSS, known exploited vulnerabilities, threat intelligence, attack paths, security hardening and compensating controls.
- An understanding of security operations, including security monitoring, alert investigation and incident response processes.
- A practical understanding of Zero Trust security principles.
- The ability to manage multiple remediation activities and maintain momentum from identification through to verified closure.
- Strong written and verbal communication skills, with the ability to explain technical risks and remediation requirements to technical and non-technical stakeholders.
- Right to live and work in the UK and ability to travel, when required, to centres.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Experience with Microsoft 365 E5/A5 security technologies, including Defender for Endpoint Plan 2 and Defender for Office 365 Plan 2.
- Experience with vulnerability assessment and management tools, preferably Qualys.
- Experience with firewall and network-security auditing tools, preferably Nipper Studio.
- Experience supporting security operations, SIEM, threat intelligence or incident investigations.
- Experience with Microsoft Intune, Entra ID, Azure or AWS security.
- Relevant certifications, such as Microsoft SC-900 or CompTIA Security+.
What Success Looks Like
- Vulnerabilities are accurately identified, risk-ranked, assigned and remediated within agreed service levels.
- Critical and actively exploited vulnerabilities receive rapid, intelligence-led attention.
- Remediation is technically verified and recurring vulnerabilities are reduced.
- Python automation shortens vulnerability triage and remediation cycles and reduces repetitive manual work.
- The SOC benefits from reliable security tooling, useful integrations and improved automation.
- Reporting provides a clear view of material exposure, remediation performance and residual risk.
- Security, Infrastructure, IT Operations and application teams share accountability for reducing security risk.
Benefits
- 25 days annual leave (based on full-time hours) PLUS bank holidays.
- 3 FI Days per year.
- Hybrid working available, equipment provided for homeworking.
- Flexible-working positive employer with a range of family-friendly policies
- Employee Assistance Programme: 24-hour confidential access to counselling and support services
- Competitive Pension
- Private Medical Insurance
- Training and development opportunities
- Long term career prospects in a growing company
- Employee perks including a range of discounts to suit your lifestyle.
First Intuition are dedicated to safeguarding children, young people, and vulnerable adults. All roles require reference checks, an enhanced DBS, and online searches in line with KCSIE guidelines. This post is exempt from the rehabilitation of Offenders Act 1974.
First Intuition is committed to safeguarding and promoting the welfare of children and vulnerable adults. All staff are expected to share this commitment and adhere to our Safeguarding and Prevent Policy, which can be viewed here.
We are a disability confident employer, committed to equal opportunities for all applicants. If you need reasonable adjustments during the recruitment process, please let us know.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London