Responsibilities
- We are looking for an experienced, hands on Senior Cyber Security Engineer to take technical ownership of our security tooling and controls the first dedicated cyber security hire in a growing in house IT and Security function.
- Reporting directly to the Head of IT & Security, this is a high autonomy role with a genuine voice in shaping our security strategy: not executing someone else's playbook, but helping to write it.
- You will own the configuration, hardening and continuous improvement of our defensive stack across a modern Microsoft and Google estate, working hands on day to day while partnering with the wider business to keep a fast growing, global organisation secure and resilient. As the function matures, there is a clear path for the right person to grow the role and, in time, a team around them.
- Security Operations & Tooling Ownership
- Incident Response & Vulnerability Execution
- Governance, Continuity & Collaboration
Requirements
- Hands on experience administering and hardening the Microsoft stack Intune, Defender for Endpoint and Entra ID as the core of a live endpoint and identity estate.
- Strong working knowledge of modern identity and access management: authentication protocols, conditional access, Entra app registrations and the Principle of Least Privilege.
- A track record of operating independently in a security or senior infrastructure role, comfortable owning and driving work with minimal oversight.
- A clear communicator who can explain technical reasoning to non technical colleagues and constructively challenge decisions, including upward.
- Experience administering and hardening Google Workspace alongside Microsoft 365.
- Familiarity with federated identity and modern authentication methods AML/OIDC, Windows Hello for Business and macOS Platform SSO.
- Working knowledge of email authentication SPF, DKIM and DMARC.
- Experience working alongside an external MDR/SOC partner for detection and incident response.
- A grounding in network security fundamentals, segmentation, wireless authentication and secure access ideally on Cisco Meraki.
- Hands on experience with vulnerability management tooling and patch/remediation workflows.
- Awareness of security governance and compliance evidence work, such as supporting audit and disclosure obligations.
- Relevant certifications (e.g. Microsoft SC 200, SC 300 or AZ 500, or equivalent)
Core Competencies
Demonstrates expertise in Cyber Security Engineering with a focus on Microsoft and Google environments, including hands on experience in security tooling, incident response, and vulnerability management. Capable of driving security strategy and governance while effectively communicating technical concepts to diverse stakeholders.