Overview
We are currently seeking an experienced Security Engineer to join a collaborative security team responsible for developing and enhancing cloud security capabilities across modern enterprise environments.
The successful candidate will play a key role in managing and evolving a Palo Alto-focused security ecosystem, supporting cloud security posture management, threat detection, incident response, and Zero Trust security initiatives across AWS and cloud-native platforms.
Please note: Previous experience working within Central Government environments is essential for this role.
Key Responsibilities
- Operate, manage and optimise Cortex Cloud/Cortex XSIAM security platforms.
- Develop and tune threat detection rules, correlation logic, and automated response playbooks.
- Manage security alert triage, incident investigations, and incident life cycle activities.
- Reduce and remediate KSPM and CSPM findings through proactive security improvements.
- Work closely with cloud engineering teams to address misconfigurations and implement security guardrails.
- Improve Kubernetes and container security posture across cloud environments.
- Integrate Cortex security findings with SIEM, ticketing, and automation platforms.
- Support and enhance Prisma Access capabilities, including: GlobalProtect, Remote Network Onboarding, Prisma Access Browser, Zero Trust Access Controls.
- Contribute to security architecture discussions and best-practice implementation across AWS environments.
Essential Skills & Experience
- Previous experience working on Central Government projects (mandatory).
- Strong hands-on experience with Palo Alto Cortex XSIAM.
- Expertise in: Data ingestion and normalisation, Correlation rule development, Automated playbook creation, Incident management and response, Security tool integrations.
- Experience with: KSPM (Kubernetes Security Posture Management), CSPM (Cloud Security Posture Management), AWS security and cloud governance, Kubernetes security benchmarking, Policy-as-Code frameworks.
- Strong knowledge of: Prisma Access, Prisma Access Browser, Palo Alto NGFW and Panorama, App-ID and User-ID technologies, Decryption policy concepts, Zero Trust Architecture.
- Solid understanding of TCP/IP Networking for investigation and troubleshooting purposes.
Desirable Experience
- Experience working within large-scale enterprise environments.
- Exposure to cloud-native security tooling and automation frameworks.
- Knowledge of security operations, cloud governance, and risk reduction programmes.
What's on Offer?
- Initial 12-month contract with strong extension potential.
- Mostly remote working arrangement with occasional London travel.
- Opportunity to work with market-leading Palo Alto security technologies.
- Competitive market rates available for suitably experienced candidates.
- Immediate interview and start opportunities.