Cyber Security Engineer
Quick Overview
Job Description
“UK CITIZENS” CV only
Role Purpose
The Cyber Security Engineer will play a key delivery role in establishing, operating and
continually improving the cyber security posture of a greenfield Microsoft tenant supporting
National Grid Strategic Infrastructure (SI). The role is responsible for implementing and
maintaining security controls in line with National Grid IT Security standards, working closely
with Security Architecture and the NG Cyber Security Incident Response Team (CSIRT). This
includes hands-on configuration, remediation activities, direct support of penetration testing /
security assessment activities and security improvements across Microsoft Intune, Entra ID,
M365, Azure, and Microsoft Purview.
This is a practitioner role, suited to someone comfortable working in an emerging environment
where controls, operating models and assurance processes are being actively matured.
Key Responsibilities
Security Controls Implementation & Operations
· Configure, maintain and operate security controls in line with National Grid IT Security
policies, standards and architectural guidance.
· Implement and remediate device, identity, access, resource and data protection controls
across Microsoft Intune, Entra ID, M365, Azure and Microsoft Purview.
· Support day-to-day security configuration tasks including Conditional Access, RBAC, privileged
access, data protection, compliance controls and Secure Score improvements.
· Identify control gaps and work with Security Architecture to design, implement and validate
suitable remediation actions.
Penetration Testing & Security Assessments
· Support end-to-end penetration testing activities, including:
o Contributing to the creation of Statements of Work (SoW) scopes for third-party penetration
testers
o Coordinating technical input, access provisioning and scoping support
o Reviewing findings and translating them into actionable remediation plans
· Own or support remediation activity for low-to-medium severity findings, escalating
higher-risk items appropriately
· Work with internal and external partners to support ongoing security assurance, risk
assessments and controls validation
Collaboration with Security Architecture & CSIRT
· Work in close alignment with Security Architects to ensure implemented controls meet
approved designs and NG security patterns
· Engage with the National Grid CSIRT team to:
o Support incident response activities where required
o Ensure alerting, logging and escalation routes are aligned with NG processes
· Support audit, assurance and control evidence activities as required
Identity, Access & Data Protection (Hands-On)
· Perform lower-level configuration and operational tasks across:
o Microsoft Entra ID (identity lifecycle, RBAC, Conditional Access, Privileged Identity
Management)
o Azure security controls and access governance
o Microsoft Purview (data classification, information protection, sensitivity labels, DLP,
eDiscovery and compliance features)
· Support and optimise Joiner/Mover/Leaver processes from a controls and access perspective
· Assist in validating secure access patterns for internal users, partners and external
collaborators
Essential Skills & Experience
Technical & Security Experience
· Hands-on experience working with Microsoft cloud security capabilities, ideally in a greenfield
or early-stage tenant.
· Practical experience with:
o Microsoft Intune device and policy hardening
o Microsoft Entra ID (formerly Azure AD)
o Microsoft 365 security and access controls
o Azure security and access controls
o Microsoft Purview compliance and data protection capabilities
· Experience with assessing and implementing CIS (Center for Internet Security) controls
· Experience supporting and remediating findings from penetration testing or security
assessments.
· Strong understanding of Identity and Access Management, least privilege and role-based
access control.
Ways of Working
· Comfortable working in evolving environments where controls, processes and tooling are
being established
· Able to translate security findings into clear, prioritized remediation actions Experience
working collaboratively across architecture, engineering, business and security teams to
improve security posture
· Strong attention to detail and an evidence-based approach to security and assurance
· Experience within a SAFE Agile delivery methodology, capable of owning, managing, refining
and prioritizing the backlog relative to their skillset with the delivery team.
· Experience in SAFE planning approaches, where work is planned in 12 weeks incremental
periods within a controlled and focused method
Desirable (but not essential)
· Experience working within regulated or critical national infrastructure (CNI) environments
· Familiarity with National Grid IT, security standards or enterprise control frameworks
· Exposure to security incident management or coordination with CSIRT functions
· Relevant security or Microsoft certifications (e.g. CCSP, SC-200, SC-300, SC-400, AZ-500
Skills
Similar jobs
IT Cyber Security Specialist
Slaughter and May · london, United Kingdom
21 minutes agoSecurity Business Analyst
Barclay Simpson · london, United Kingdom
1 hour agoSecurity Engineer
Laxmi Venture Capital · Leicester, United Kingdom
2 hours ago£40k - £45k/yrService Engineer - Security
Johnson Controls · Nottingham, United Kingdom
2 hours agoFire and Security Engineer
Alecto Recruitment · Harlow, United Kingdom
4 hours agoFire and Security Engineer
Alecto Recruitment · Billericay, United Kingdom
4 hours ago