Uptime Solutions Ltd

Cyber Security & Vulnerability Management Engineer

RemoteSouth AfricaFull-time
ZAR 38,000 - ZAR 42,000 monthly
About the Job
Job Description: Cyber Security & Vulnerability Management Engineer

Role Overview:
We are seeking a technically skilled Cyber Security & Vulnerability Management Engineer to support the delivery of enhanced security services for customers progressing through Cyber Essentials Plus (CE+) certification.

The successful candidate will be responsible for monitoring customer environments, identifying vulnerabilities, coordinating remediation activities, and maintaining security standards across server, workstation, and Microsoft 365 environments.

This role will sit within a proactive security function, working closely with internal teams and customers to ensure vulnerabilities are identified, prioritised, and remediated in line with Cyber Essentials Plus requirements.
The ideal candidate will have experience working with vulnerability scanning platforms, endpoint management tools, Microsoft 365 security controls, and proactive infrastructure monitoring.

Key Responsibilities:
Vulnerability Management & Remediation:
  • Monitor customer estates using vulnerability scanning platforms to identify security weaknesses.
  • Review vulnerability reports, assess risk, and prioritise remediation activities.
  • Perform remediation activities using endpoint management and patching platforms.
  • Coordinate and execute patch deployments across customer environments.
  • Manage remediation activities requiring planned maintenance windows, including occasional out-of-hours changes and reboots.
  • Maintain accurate records of vulnerabilities, actions taken, and resolution status.

Cyber Essentials Plus Support:
  • Support customers through Cyber Essentials Plus certification requirements.
  • Monitor customer environments against Cyber Essentials Plus controls.
  • Identify security gaps relating to:
    • Vulnerability management
    • Patch compliance
    • Multi-factor authentication (MFA)
    • Account security
    • User access controls
    • Secure configuration standards
  • Assist with maintaining customer readiness for external CE+ audits.

Security Monitoring:
  • Monitor customer server and workstation environments for security risks.
  • Review security alerts and investigate potential issues.
  • Support proactive identification of security improvements.
  • Assist with security baselining and compliance monitoring across Microsoft 365 environments.

Microsoft 365 Security:
  • Monitor Microsoft 365 security posture using security assessment and alerting platforms.
  • Review findings relating to:
    • MFA compliance
    • Account sharing
    • Identity security
    • Configuration weaknesses
  • Support customers in improving their Microsoft 365 security posture.

Required Experience & Skills:
The successful candidate will ideally have:
Essential:
  • Experience working within an IT support, infrastructure, NOC, or security operations environment.
  • Hands-on experience with vulnerability scanning tools.
  • Experience with endpoint management and patching solutions.
  • Strong understanding of Windows environments, servers, and workstations.
  • Experience investigating and resolving security vulnerabilities.
  • Ability to work independently and manage remediation tasks across multiple customer environments.

Technical Experience:
Experience with the following technologies would be highly desirable:
  • NinjaOne / Ninja RMM or similar endpoint management platforms.
  • Nessus by Tenable or similar vulnerability scanning solutions.
  • ConnectSecure or equivalent vulnerability assessment platforms.
  • Microsoft 365 security tooling.
  • Cyber Essentials / Cyber Essentials Plus requirements.
  • Patch management processes.
  • Security hardening and best practice configuration.

Desirable Experience & Certifications:
The following would be advantageous but are not essential:
  • Experience supporting Cyber Essentials Plus assessments.
  • Experience working with IASME requirements.
  • Exposure to ISO 27001 standards or security auditing.
  • Cyber security certifications such as:
    • CompTIA Security+
    • Microsoft Security certifications
    • Cyber Essentials Practitioner
    • Other relevant security qualifications.

Working Hours:
  • Standard working hours: UK business hours (8:00am–5:00pm or 8:30am–5:30pm).
  • Primarily a daytime role, with flexibility required occasionally for:
    • Scheduled maintenance.
    • Patch deployments.
    • Customer remediation activities requiring system reboots.
  • Time off in lieu (TOIL) provided for additional hours worked outside standard schedules.

Candidate Profile:
We are looking for someone who is:
  • Security-minded with a proactive approach.
  • Comfortable working independently.
  • Detail-oriented with strong analytical skills.
  • Able to investigate vulnerabilities and drive remediation through to completion.
  • Interested in developing within cyber security and vulnerability management.
  • Able to communicate clearly with technical and non-technical stakeholders.

While certifications are beneficial, the strongest candidates will be those with practical experience, strong technical curiosity, and the ability to understand and improve customer security environments.