About this role
Salary: £55,000 - 59,000 per year
Requirements: 5+ years in a hands-on cybersecurity engineering or security architecture role.Proven experience managing WAF and edge security at scale, using Cloudflare, Akamai, or equivalent platforms.Deep hands-on experience with Microsoft Defender for Cloud, Entra ID, Conditional Access policies, and Azure app registrations.Practical knowledge of API security, OWASP Top 10 remediation, and secure web application design.Experience working embedded in engineering or platform teams within an Agile/DevOps environment.Familiarity with AI and LLM security risks and emerging best practices for securing AI-powered systems.Experience working with or alongside outsourced MDR or SOC providers.Exposure to identity governance practices including access reviews, lifecycle management, and role-based access control.Experience in a healthcare, dental, or regulated industry context is a strong plus.Ability to communicate security risk clearly to non-technical stakeholders without resorting to jargon.Pragmatic approach to risk: knows when to enforce, when to escalate, and when to accept, without becoming a blocker.A collaborator first: builds trust with engineering, product, and platform teams rather than policing them.A role model of the organisations people values who brings a calm, measured approach to incidents and a genuine curiosity for the threat landscape. Responsibilities: Own and maintain WAF configuration across Cloudflare and Akamai, tuning rules and responding to emerging threats.Review and improve web ingress controls including DDoS mitigation, rate limiting, and certificate management.Apply OWASP principles across the organisations web applications, working with development teams to identify and remediate vulnerabilities.Lead API security design and governance, ensuring consistent security controls across platform APIs.Own Azure security posture using Microsoft Defender for Cloud, identifying and remediating risks across the hybrid estate.Define and maintain security baselines for Azure workloads, virtual networks, and on-premise systems in transition.Work with the Platform Engineering team to ensure cloud infrastructure is built and deployed securely, including network segmentation and least-privilege controls.Own and maintain Entra ID configuration, Conditional Access policies, Access Packages, and app registrations across the organisation.Define and enforce identity governance standards, ensuring access reviews, lifecycle management, and role hygiene are maintained.Work with the wider engineering team to ensure application-level identity is implemented consistently and securely.Define security guardrails and controls for the organisations AI and automation capabilities, covering data handling, prompt injection risks, and model access controls.Work with the AI and Automation Lead to ensure AI solutions are designed and deployed with security by design from the outset.Stay current with AI security risks and emerging attack vectors, translating threat intelligence into practical controls.Embed security into CI/CD pipelines and DevOps workflows, championing shift-left practices across engineering teams.Define and maintain security standards, patterns, and guidelines for use across platform and product delivery.Participate in architecture and design reviews, providing security input as part of the delivery lifecycle.Act as the internal interface for Arctic Wolf, our outsourced MDR provider, triaging escalations and feeding intelligence back into the engineering environment.Use intelligence from Arctic Wolf and external sources to proactively harden controls before threats materialise.Monitor the external threat landscape relevant to the healthcare and dental sector. Technologies: AIAPIAzureCI/CDCloudDevOpsEmbeddedLLMNetworkOWASPSecurityWAFWeb More:
We are a leading healthcare and dental care provider, and this Senior CyberSecurity Engineer role sits at the intersection of infra, product, and delivery teams. Reporting to the Director of IT, we are looking for someone to keep our organisation secure without slowing it down by hardening web ingress controls, securing identity and access, and building security guardrails for AI adoption. Day-to-day security monitoring is handled by our SOC team, while this role focuses on owning Azure security posture, managing WAF and edge security, and embedding security into how we build and run software.
last updated 29 week of 2026