Senior Security Engineer
You will strengthen security posture by designing, implementing, and improving security controls, identity services, cloud security solutions, and governance processes. You will manage identity and access, cloud and endpoint security, vulnerability management, automation, security monitoring, risk assessments, threat modelling, and compliance activities. You will also advise stakeholders, maintain security platforms, and develop infrastructure-as-code and automated security workflows.
Responsibilities
- Design, implement, and maintain Identity and Access Management solutions
- Manage permission settings and access controls
- Configure security systems according to requirements and best practices
- Assess cloud and endpoint security configurations against CIS, STIG, SOC2, and internal standards
- Own the administration, configuration, and lifecycle management of security platforms
- Maintain inventories of security tooling and integrations
- Evaluate technologies and recommend security enhancements
- Troubleshoot security platform issues with vendors and stakeholders
- Advise technical teams, business stakeholders, and senior leadership on security architecture, risk reduction, and compliance
- Create and update security policies and procedures
- Manage vulnerability activities across cloud infrastructure, endpoints, SaaS applications, and identity platforms
- Prioritise and coordinate remediation efforts
- Conduct security assessments and threat modelling
- Produce security posture, control effectiveness, and remediation reports
- Develop automation using PowerShell, Python, Bash, and APIs
- Design, implement, and support Terraform and cloud-native Infrastructure as Code solutions
- Integrate security telemetry into Microsoft Sentinel
- Develop automated governance, compliance, and incident response workflows
Requirements
- Extensive Microsoft Entra ID and Identity Governance experience
- Experience securing AWS environments
- Experience with Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Intune, and Azure Security services
- PowerShell, Bash, and Python scripting
- System and application hardening using CIS and STIG standards
- SaaS security administration using SSO, SCIM provisioning, Conditional Access, entitlement governance, and lifecycle management
- Endpoint security across Windows and macOS environments
- Enterprise network security using firewalls, WAF, SWG, ZTNA, DNS security, and cloud-native network controls
- Experience configuring Secure Web Gateways such as Zscaler, iBoss, or Netskope
- Experience with binary execution control solutions such as AppLocker, Defender Application Control, Santa, or ThreatLocker
Benefits
- Hybrid working model
- 35 days of paid time off per year inclusive of annual leave and public holidays
- One additional day of annual leave for each year of service
- Comprehensive medical insurance including dental, optical, audiology, and mental health coverage
- Life insurance
- Enhanced pension contributions with employer matching
- 24/7 Employee Assistance Programme