We're on a mission to make a big green dent in the universe by building a truly sustainable energy system globally.
That means making power greener, smarter, and more affordable for everyone.
We put customers at the heart of everything we do: with always-fair prices, transparency and outrageous customer service.
We drive system change: with transformative tech to make renewable energy the norm and end global reliance on fossil fuels.
Octopus Energy Group is made up of 10 businesses spanning 6 countries across 3 continents, including: Octopus Energy Retail, Kraken Technologies, Octopus Energy Generation, Kraken Flex, Octopus Electric Vehicles, and the Octopus Centre for Net Zero. More on OEG @ octopusenergy.group
Help us use technology to make a big green dent in the universe! It’s a really exciting time in energy. Help us make a real impact on shaping a better, more sustainable future.
We are very excited to be building a small and efficient Cyber and Information Security team at Octopus Energy Group. We're hiring for both Mid-Level and Senior Security Engineers. We are looking for ambitious, knowledgeable, and experienced Security Engineers to join our team, to grow with the rest of the company, and ensure we continue to do so in a secure and safe way.
You will be a key partner in defining what Security is at Octopus Energy Group. We will be shaping this team to provide a world class support service to our employees, building our way out of problems with engineering firepower and undertaking transformational organisational change.
You’ll play a crucial role in helping to secure our software development processes, securing our platform services, integrating security practices, and shaping a culture of security. This is a creative, and collaborative position that is a full-time member of a Cloud-First organisation. If you’re passionate about Cloud technologies and driving security by design, we encourage you to apply!
Specifically, we're looking for Security Engineers with at least 2 years of relevant experience to help us improve security across the Octopus Energy Group. Senior Security Engineers should bring 4+ years of relevant experience.
Our process usually takes up to 4 weeks, but we’ll always do our best to flex around what works for you. Along the way, you’ll chat with our recruitment team and your Recruiter will help you throughout different stages. Got any burning questions before then? Drop us a message at
[email protected] and we’d love to help!
If this sounds like you then we'd love to hear from you. 🚀
Are you ready for a career with us? We want to ensure you have all the tools and environment you need to unleash your potential. Need any specific accommodations? Whether you require specific accommodations or have a unique preference, let us know, and we'll do what we can to customise your interview process for comfort and maximum magic!
Studies have shown that some groups of people, like women, are less likely to apply to a role unless they meet 100% of the job requirements. Whoever you are, if you like one of our jobs, we encourage you to apply as you might just be the candidate we hire. Across Octopus, we're looking for genuinely decent people who are honest and empathetic. Our people are our strongest asset and the unique skills and perspectives people bring to the team are the driving force of our success. As an equal opportunity employer, we do not discriminate on the basis of any protected attribute. Our commitment is to provide equal opportunities, an inclusive work environment, and fairness for everyone.
What you'll do:
Build and maintain security tooling and infrastructure to improve our overall security postureRespond to security incidents and help improve incident processesWork with the wider Platform and application teams to ensure that our infrastructure, systems, and applications are secureDevelop secure coding practices and provide guidance to development teams on application security best practicesKeep up to date with the latest security trends and technologies related to application security, and evaluate their potential impact on our systems and dataDevelop and maintain security documentation related to application security, including policies, procedures, and guidelines
This is a varied role in a growing team. You’ll have the opportunity to get involved in other security-related projects and initiatives as needed. We encourage you to take on new challenges that align with your skills and internests, and to collaborate with other teams to drive improvements in security across our entire organisation
What you'll have:
Excellent security and technology backgroundStrong understanding of web application security concepts, including OWASP Top 10 vulnerabilities, secure coding practices, and application security testing toolsExperience with security tools and technologies, such as web application firewalls (WAFs), and static and dynamic application security testing (SAST/DAST) toolsExperience in endpoint (e.g. EDR and ZTNA) and cloud (e.g. CSPM and CNAPP) security toolingExperience security SaaS solutionsGood AWS experience (or knowledge) and familiarity with various AWS security services (or familiarity with Azure and/or GCP with a willingness to learn AWS)Strong analytical and problem-solving skills, with the ability to identify and mitigate security risks
A good candidate will have experience in at least some of the areas mentioned, we’re not expecting any candidate to be an expert in all areas!
What will help:
Security certifications (any of the famous abbreviations) Certifications from cloud providers’ certification pathsSecurity qualifications (e.g. apprenticeships or degrees)Experience with preparing high quality documentationExperience using logging tools (whether this was a SIEM system or not) to generate alerts and reportsKnowledge of the MITRE ATT&CK framework 💚 Why else you'll love it here
💰 Wondering what the salary for this role is? Just ask us! On a call with one of our recruiters it's something we always cover as we genuinely want to match your experience with the correct salary. The reason why we don't advertise is because we honestly have a degree of flexibility and would never want salary to be a reason why someone doesn't apply to Octopus - what's more important to us is finding the right octofit!🎉 Octopus Energy Group is a unique culture. An organisation where people learn, decide, and build quicker. Where people work with autonomy, alongside a wide range of amazing co-owners, on projects that break new ground. We want your hard work to be rewarded with perks you actually care about! We were recently named the UK's top company to work for, and we ranked in the top ten in the Sunday Times Best Places to Work 2024. Our Group CEO, Greg has recorded a podcast about our culture and how we empower our people. We’ve also been placed in the top 10 companies for senior leadership🎁 Visit our UK perks hub - Octopus Employee Benefits