Rodeo
Get started

Hodge

Senior Cyber Security Engineer

Cardiff
Posted about 18 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Do you want to be part of a force for good, helping to make life better for customers and society in the moments that matter?

At Hodge, we put people at the heart of our business, and that means our customers, colleagues and communities. Hodge is a Welsh financial services provider focused on real estate finance and specialist residential mortgage markets.

The Role

The role of Senior Cyber Security Engineer is to ensure that all internal and external applications, infrastructure, and data are managed in line with cyber and information security best practice and that the estate is pro-actively upgraded and maintained.

The role, under the overall management of the Security Architect, will lead the Cyber Security engagement and activity across Hodge to ensure that new and amended services are built and taken live with the appropriate level of control. Engage with internal and external stakeholders to drive continual improvement of cyber security and related practices.

Essential Criteria

  • Relevant IT or computer science degree.
  • Experience of working to recognised cyber security and risk framework.
  • Experience of implementing relevant tools for Cyber controls.
  • Knowledge in IT security best practice, solutions and frameworks.
  • Ability to demonstrate understanding of vulnerability remediation.
  • Knowledge and experience of developing for AWS or similar cloud platforms.

Key Responsibilities

  • Manage implementation and ongoing operation of appropriate cyber security toolset covering user, infrastructure and application activity.
  • Manage implementation and operation of vulnerability management processes across applications and infrastructure.
  • Work with outsourced security providers to ensure work being undertaken is of required standard and appropriate reporting is available.
  • Develop, maintain and manage the Security Controls Catalogue to ensure consistent reporting of risks and controls, and alignment to best practice.
  • Develop, maintain and manage the Security Roadmap to provide visibility and control of ongoing security enhancements.
  • Ensure that all evidence of controls and cyber operations is maintained to support external and internal audit assessments.
  • Ensure appropriate documentation is maintained to support current and future activity.
  • Ensure work includes appropriate quality control mechanisms and automated reporting; ensure existing technical controls and process are effective, co-ordinating and remedial work required.
  • Lead the security awareness programme for Hodge colleagues ensuring that ongoing learning materials are developed and enhanced as required. Undertake regular testing exercises with colleagues to measure assimilation and awareness.
  • Ensure that Cyber security activity undertaken supports visibility, transparency and suitable metrics on cyber controls and activity.
  • Undertake assurance assessments of third-party suppliers.
  • Manage and report the benefits, risks and alternatives of relevant frameworks, tools and languages.
  • Review work of other cyber team members to ensure quality standards are maintained and knowledge transfer.
  • Work with Service Delivery and Development teams to assist in the investigation and resolution of live issues and to support BAU activity.
  • Work with Service Delivery team to ensure Service Transition controls and documentation are provided in line with agreed Service Transition framework.
  • Work with Service Delivery and Technology Project colleagues on implementation and planning of cyber related tools and projects.
  • Work with business and IT stakeholders to ensure security provision and tools align with short and longer-term goals.
  • Work with software and delivery teams to provide cyber security and controls guidance across development and infrastructure projects.
  • Engage with software teams to define controls to be applied as part of software development and delivery.
  • Work with delivery teams to agree security NFRs (authentication, confidentiality, integrity, etc.) and ensure required operational controls are defined, agreed, tested and implemented.
  • Engage with external suppliers to utilise external expertise where required across delivery and live operation.
  • Understand core architectural patterns, frameworks and architecture used by Hodge and understand the security implications.
  • Develop and implement threat modelling and risk analysis framework.
  • Ensure that defined security standards are applied to all work undertaken (e.g. password policy, authentication standards)
  • Work with 3rd party suppliers to manage penetration test planning, execution and evaluation of results.
  • Engage with and contribute to relevant cyber and tech community forums.
  • Advise and coach other team members to aid their technical and team development.
  • Pro-actively investigate technology landscape and best practice to identify improvements.
  • Maintain a knowledge of current Cyber technologies and best practice to identify improvements.
  • Engage with external parties to share and improve knowledge.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Please be aware that should we pursue your application, all our Financial Services employees will be expected to complete background checks to assess suitability for employment, these include; a criminal record, identity, media, sanctions, adverse finance, fraud prevention and reference checks to comply with our regulatory requirements.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Hodge is an advocate of being an equal opportunities employer. We believe in promoting equality and diversity which is central to our lives today. We welcome applications from all sections of the community and recognise the value a diverse workforce brings to an organisation.

ESG and sustainability are at the heart of everything we do and serves as a reminder of the responsibility we have to our stakeholders, customers, colleagues and the communities we operate in to use our position wisely. We’re currently exploring different certifications available and have done an initial review of how we think we’d fare, as we see this as a real opportunity for Hodge given our social purpose.

Apply today to become part of Hodge’s mission to make life better for customers and society in the moments that matter.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security
Vulnerability Management
AWS
Risk Frameworks
Threat Modelling
Security Controls
Penetration Testing
Security Architecture
Cloud Security
Audit Compliance
Stakeholder Management
Security Awareness Training

Location

Cardiff, Wales, United Kingdom

Sign up to applySee more jobs like this