Role Purpose
The Cyber Security Engineer will play a key delivery role in establishing, operating and continually improving the cyber security posture of a greenfield Microsoft tenant supporting National Grid Strategic Infrastructure (SI).
The role is responsible for implementing and maintaining security controls in line with National Grid IT Security standards, working closely with Security Architecture and the NG Cyber Security Incident Response Team (CSIRT).
This includes hands-on configuration, remediation activities, direct support of penetration testing / security assessment activities and security improvements across Microsoft Intune, Entra ID, M365, Azure and Microsoft Purview.
This is a practitioner role, suited to someone comfortable working in an emerging environment where controls, operating models and assurance processes are being actively matured.
Technical & Security Experience
- Hands-on experience working with Microsoft cloud security capabilities, ideally in a greenfield or early-stage tenant.
- Practical experience with:
- Microsoft Intune device and policy hardening
- Microsoft Entra ID (formerly Azure AD)
- Microsoft 365 security and access controls
- Azure security and access controls
- Microsoft Purview compliance and data protection capabilities
- Experience with assessing and implementing CIS (Center for Internet Security) controls
- Experience supporting and remediating findings from penetration testing or security assessments.
- Strong understanding of Identity and Access Management, least privilege and role-based access control.
Desirable (but not essential)
- Experience working within regulated or critical national infrastructure (CNI) environments
- Familiarity with National Grid IT, security standards or enterprise control frameworks
- Exposure to security incident management or coordination with CSIRT functions
- Relevant security or Microsoft certifications (e.g. CCSP, SC-200, SC-300, SC-400, AZ-500)