Security Engineer (m/w/d)

Remote, DE
Platform 🛜 – Security /
Full-time /
Remote
Help us use technology to make a big green dent in the universe!

Kraken powers some of the most innovative global developments in energy.

We’re a technology company focused on creating a smart, sustainable energy system. From optimising renewable generation, creating a more intelligent grid and enabling utilities to provide excellent customer experiences, our operating system for energy is transforming the industry around the world in a way that benefits everyone.

It’s a really exciting time in energy. Help us make a real impact on shaping a better, more sustainable future. 

Kraken Customer

What we do: build the most AI-driven, innovative, forward-thinking platform for energy management. From optimizing resources to delivering cost-effective, exceptional customer experiences through advanced Customer Information Systems (CIS), billing, meter data management, CRM, and AI-driven communications, Kraken is powering the next wave of innovation in the energy industry.

Why we do it: future energy will not look like energy as we know it today. We need to not just think about our future, but build for it. Now.

We are seeking experienced Senior Security Engineers that will become a member of a small but growing Cyber Security Team in Kraken Technologies. You’ll play a crucial role in helping to secure our software development processes, securing our platform services, integrating security practices, and shaping a culture of security. This is a creative, and collaborative position that is a full-time member of an AWS-focused, agile engineering organisation. If you’re passionate about Cloud technologies and driving security by design, we encourage you to apply!

Specifically, we're looking for a Senior Security Engineer with at least 4 years of relevant experience to help us improve security across Kraken Technologies and the wider Octopus Energy Group.

What you’ll do

    • You will be supporting the following activities:
    • Build and maintain security tooling and infrastructure to improve our overall security posture
    • Respond to security incidents and help improve incident processes
    • Work with the wider Platform and application teams to ensure that our infrastructure, systems, and applications are secure
    • Develop secure coding practices and provide guidance to development teams on application security best practices
    • Keep up to date with the latest security trends and technologies related to application security, and evaluate their potential impact on our systems and data
    • Develop and maintain security documentation related to application security, including policies, procedures, and guidelines

    • This is a varied role in a growing team. You’lll have the opportunity to get involved in other security-related projects and initiatives as needed. We encourage you to take on new challenges that align with your skills and internests, and to collaborate with other teams to drive improvements in security across our entire organisation

What you’ll have

    • Good experience in at least some of the areas mentioned above (we’re not expecting any candidate to be an expert in all areas)
    • Excellent information security and technology background
    • Strong understanding of web application security concepts, including OWASP Top 10 vulnerabilities, secure coding practices, and application security testing tools
    • Experience with security tools and technologies, such as web application firewalls (WAFs), static and dynamic application security testing (SAST/DAST) tools, and vulnerability scanners
    • Good AWS experience and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS)
    • Knowledge of industry and regulatory security standards, such as ISO 27001, SOC2, and GDPR
    • Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks
    • Some experience in software development or Cloud Engineering, demonstrating a strong foundation security best practices

What will help

    • Security certifications (any of the famous abbreviations)
    • Certifications from cloud providers’ certification paths
    • Security qualifications (e.g. apprenticeships or degrees)
    • Experience with preparing high quality documentation
    • Experience using logging tools (whether this was a SIEM system or not) to generate alerts and reports
    • Experience working in organisations that maintain ISO 27001 and/or SOC 1 and SOC 2 type II certifications
    • Knowledge of the MITRE ATT&CK framework
As we are an international organization, we  kindly ask you to send us your CV in English

If this sounds like you then we'd love to hear from you.

Are you ready for a career with us? We want to ensure you have all the tools and environment you need to unleash your potential. Need any specific accommodations? Whether you require specific accommodations or have a unique preference, let us know, and we'll do what we can to customise your interview process for comfort and maximum magic!

Studies have shown that some groups of people, like women, are less likely to apply to a role unless they meet 100% of the job requirements. Whoever you are, if you like one of our jobs, we encourage you to apply as you might just be the candidate we hire. Across Octopus, we're looking for genuinely decent people who are honest and empathetic. Our people are our strongest asset and the unique skills and perspectives people bring to the team are the driving force of our success. As an equal opportunity employer, we do not discriminate on the basis of any protected attribute. Our commitment is to provide equal opportunities, an inclusive work environment, and fairness for everyone.