Description
It's easy to misunderstand what Nationwide is like. Why? Because we're not like a bank. We're not like other financial services companies either. As a Senior Security Engineer here, you'll sit within CTO, assisting a wide range of delivery teams in engineering secure solutions and protecting our member's money and data.
We believe security is a systemic concern; therefore, security problems should be solved by a systemic approach (take a look at our tenets here if you are interested to learn more about our vision). We will have regular forums in which we consult with other security engineers within the team, looking at the problems from each of our specialities' perspectives.
At Nationwide we offer hybrid working wherever possible. More rewarding relationships are supported through our hybrid approach, bringing colleagues together across our UK wide estate, whilst also supporting generous access to home working. We value our time in the office to solve problems, to learn, and to feel connected.
For this job you'll spend at least two days per week, or if part time you'll spend 40% of your working time, based at either our Swindon, London, Manchester or Glasgow offices. If your application is successful, your hiring manager will provide further details on how this works. You can also find out more about our approach to hybrid working here.
This role can be based from our Manchester or Glasgow offices with the view you'll be available for ad/hoc visits to our Swindon and London offices.
If we receive a high volume of relevant applications, we may close the advert earlier than the advertised date, so please apply as soon as you can.
What you’ll be doing
As a senior security engineer, you will work cross-functionally to assess risk and help deliver countermeasures that protect our member's data. You will work will engineering teams to create solutions that solve or remediate security problems. This will involve a range of activities, including (but not limited to) threat modelling, selection and configuration of DevSecOps tools, high-level and detailed security designs.
About you
We are looking for a Senior Security Engineer with experience in design and implementing cloud native applications in the cloud.
You should have demonstrable experience in
- Threat modelling, design and implementing security controls in the cloud environment (AWS or Azure)
- Design and implementing cloud native and hybrid solutions in major public cloud platforms.
- Understanding of cryptographic primitives and protocols and their implementations in the cloud environment
- Programming with at least one modern language, an appreciation of software development lifecycle, software delivery methodologies and experience with industry-standard tools and methods for delivering software in an enterprise environment (version control, CI/CD pipeline, etc.)
- Experience with Authentication and authorisation, Attribute-Based Access Control (ABAC), Role Based Access Control (RBAC))
- Teamwork skills and resourcefulness with a proven sense of ownership and drive
Our Customer First behaviours are all about putting customers and members at the heart of how we work together. You can strengthen your application by showing the behaviours that resonate with you, and how you might have already demonstrated these.
- Say it straight - This is about being honest and direct with good intent and saying what needs to be said in the room. It’s also about being clear, precise, and using language that we and, importantly, our customers and members can understand.
- Push for better - This is about aiming high and constantly looking for better in how we work together and serve our customers and members.
- Get it done - This is about prioritising what will have the greatest impact, being decisive and taking accountability for delivering on the end-to-end outcome.
We know applying for jobs can sometimes feel like you’re sending an application into a black hole. We review each application individually. So, it’s a good idea to call out your most relevant experience on your application to give yourself the best chance.
The extras you’ll get
There are all sorts of employee benefits available at Nationwide, including:
- A personal pension – if you put in 7% of your salary, we’ll top up by a further 16%
- Up to 2 days of paid volunteering a year
- Life assurance worth 8x your salary
- A great selection of additional benefits through our salary sacrifice scheme
- Access to an annual performance related bonus
- Access to training to help you develop and progress your career
- Wellhub – Access to a range of free and paid options for health and wellness.
- 25 days holiday, pro rata
What makes us different
Nationwide is the world’s largest building society. With over 15 million customers, we have a relationship with almost a quarter of the UK’s population. We’ve got the scale to compete with the big banks, but we’re not a bank.
As a building society, we’re owned by our members – that’s our customers who have their current account, mortgage or savings with us. It means we can do things differently to deliver our Purpose – Banking – but fairer, more rewarding, and for the good of society.
When you work at Nationwide, you can experience that difference for yourself. You’ll be part of a high-performing, purpose-driven organisation that offers rewarding career experiences and a highly competitive range of benefits to match. You’ll also be joining us at an important time as we seek to reach more and more people in the UK. We want everyone in the UK to know that they don’t have to bank with a bank. They can choose a modern mutual instead.
What to do next
If this role is for you, please click the ‘Apply Now’ button. You’ll need to attach your up to date CV and answer a few quick questions for us.
We respond to everyone, so we will be in contact shortly after the closing date to let you know the outcome of your application. If you’re selected, we’ll have a short technical screening call. The next step is a competency-based interview followed by a case study, which you’ll be given in advance to work on and present in the discussion.
#li-post