About this role
Salary: £56,000 - 96,000 per year
Requirements: 5–10 years in cloud or infrastructure security roles.Deep experience with Defender for Cloud, Sentinel, and Azure security configurations.Strong knowledge of Microsoft Entra ID, AD DS, RBAC, and hybrid identity security.Hands-on experience with EDR (MDE), CSPM tools, and vulnerability management platforms.Practical understanding of Zero Trust architecture and secure-by-design methodologies.Familiarity with PCI DSS, NIST, and ISO 27001 frameworks.Awareness of AWS security fundamentals (Guard Duty, KMS, IAM Identity Center) (desirable).Experience with Infrastructure as Code (IaC) security (Terraform, Bicep) and DevSecOps practices (desirable).Scripting for automation using PowerShell or Python (desirable).Bachelors degree in Computer Science, Information Security, or equivalent experience.Preferred certifications include AZ-500, SC-300, SC-100, or CISSP/CCSP.Analytical mindset with the ability to remain composed under pressure during security incidents.Excellent communication skills to engage with diverse stakeholders across the technology organization. Responsibilities: Design and implement security controls across Azure, on-prem servers, and SaaS applications while maintaining hardening standards based on CIS and NIST benchmarks.Define standards for Entra ID and Active Directory, overseeing requirements for Conditional Access, MFA, SSO, and PIM.Own and operate the SIEM/SOAR stack, including Microsoft Sentinel and Defender XDR, to develop detection rules and support forensic investigations.Enforce secure baselines across virtualized environments (VMware/Hyper-V), Windows Servers, and Azure IaaS workloads.Manage the certificate lifecycle (PKI/AD CS) and implement data classification and DLP strategies using Microsoft Purview.Manage Azure Landing Zone security and connectivity, collaborating with Network Engineering to validate secure firewall and VPN configurations.Support audit readiness for ISO 27001, PCI DSS, and Cyber Essentials Plus, ensuring all remediation progress is tracked and documented. Technologies: AWSActive DirectoryAzureCloudDevSecOpsFirewallHyper-VIAMIaaSSupportNetworkPowerShellPythonRBACSecurityTerraformVPNVMwareWindowsFabric More:
We are a leading UK retail organization undergoing a significant digital transformation. We seek a technical and hands-on Senior Security Engineer to design, implement, and operate robust security controls across a complex hybrid environment. In this role, you will bridge the gap between strategy and execution and collaborate closely with Network, Infrastructure, and Application teams to ensure that secure-by-design solutions are integrated across the ecosystem. We value diversity and strive to create an inclusive environment for all our employees.
last updated 32 week of 2026