The Opportunity
We're supporting a leading organisation operating within a highly regulated and nationally significant environment as they continue to build and mature a new Microsoft cloud security estate.
This is a hands-on Security Engineer position suited to someone who enjoys improving security posture, implementing controls and solving security challenges in an evolving environment. You'll play a key role in strengthening the organisation's cyber security capabilities while helping prepare the environment for an upcoming penetration test programme over the next 3-6 months.
The team are looking for someone who can work autonomously, identify potential weaknesses before they become audit or pen-test findings, and drive remediation activities from start to finish.
Key Responsibilities
- Implement, configure and maintain security controls across the Microsoft security ecosystem.
- Identify security gaps and drive remediation activities to improve overall security posture.
- Support the preparation, coordination and remediation of external penetration testing engagements.
- Implement and manage identity, access management and privileged access controls.
- Configure and maintain Conditional Access, RBAC and Privileged Identity Management controls.
- Improve device, identity, data and cloud security controls across the estate.
- Support audit, assurance and compliance activities.
- Work closely with architecture, security operations and wider technology teams to deliver security improvements.
- Contribute to security hardening initiatives and CIS control implementation.
Essential Skills & Experience
- Strong Security Engineering background.
- Hands-on experience with:
- Microsoft Entra ID
- Microsoft Intune
- Microsoft 365 Security
- Microsoft Azure
- Microsoft Purview
- Experience implementing and assessing CIS security controls.
- Previous experience remediating vulnerabilities and penetration testing findings.
- Strong understanding of:
- Identity & Access Management (IAM)
- RBAC
- Privileged Access Management
- Least Privilege principles
- Experience working in cloud-first Microsoft environments.
- Ability to work independently and proactively identify security improvements.
- Strong stakeholder engagement and communication skills.
Desirable Experience
- Experience preparing environments ahead of external penetration testing.
- Exposure to regulated, critical infrastructure or highly secure environments.
- Experience working alongside Security Operations or Incident Response teams.
- Microsoft or security certifications such as SC-200, SC-300, SC-400, AZ-500, CISSP or CCSP.
Suitable Backgrounds
- Security Engineer
- Cloud Security Engineer
- Microsoft Security Engineer
- Identity & Access Management Engineer
- Azure Security Engineer
- Cyber Security Engineer
who enjoys hands-on technical delivery and taking ownership of security improvements within a developing environment.