Cyber Defence Network Engineer

Grant Thornton (UK)

Greater London

On-site

GBP 60,000 - 90,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Grant Thornton UK invites a skilled Network Engineer to join our Cyber Defence Centre in the UK. This hands-on role covers incident containment, security assessment, and the delivery of managed security solutions across client environments.

You will help implement Zero Trust, SASE, and cloud/workload security using modern tooling and cross-functional collaboration with DFIR/SOC teams.

Qualifications

  • Background in network engineering with security outcomes.
  • Active pursuit or holding NCCSI certification.
  • Industry-recognised security and networking qualifications desirable.

Responsibilities

  • Deliver containment and recovery for live client incidents with emphasis on rapid remediation.
  • Perform security reviews and hardening across multi-cloud and on-premises estates.
  • Design and implement security solutions from discovery to handover for client environments.
  • Work on Zero Trust, SASE, and data protection initiatives within client networks.

Skills

LAN/WAN
VLAN segmentation
Layer 2/3 access
Routing & Switching
DMZ architecture
DNS/DHCP
Firewall design
Cisco Firepower
Palo Alto
FortiGate
SASE
Zero Trust
Netskope One
CASB
Entra ID
Azure
Azure Firewall
Azure NSGs
M365 & Entra ID
AWS
Oracle Cloud
Terraform
CrowdStrike Falcon
EDR
RBAC
NIST CSF
CIS Benchmarks
ISO27001

Education

NCCSI certification
CCNA
CCENT
AWS Cloud Practitioner
AZ-900
SC-900
OCI Foundations
MCTS
ITIL Foundation

Tools

Prowler
ScubaGear
PingCastle

Job description

Alternatively, Grant ThorntonAt Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.Job Description:Network Engineer, Cyber Defence CentreAlternatively, Grant ThorntonAt Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.About usThe Grant Thornton Cyber Defence Centre is an award-winning* managed security services provider operating at the forefront of cyber security, using industry-leading technologies to protect and support our clients. Alongside our SOC capability, we have cutting-edge incident response teams delivering rapid cyber breach investigations for clients through insurance panels and direct engagements, supporting organisations at their most critical moments.We invest heavily in our people, offering clear progression opportunities and encouraging initiative within a collaborative, cross-functional environment with a strong team ethos. Support is always available across the SecOps, DFIR, MSS and wider cyber teams.We’re seeking an experienced Network Engineer to join our Cyber Defence Centre. This is a hands-on technical role that spans live incident response, security assessment and hardening, and the design and delivery of managed security solutions in client environments. You will be one of the people clients rely on to shut an attacker out of their estate and then help make sure it does not happen again.A look into the roleAs a Network Engineer within the Cyber Defence Centre, you will deliver the containment and recovery phases of live client incidents, and work on assessment, hardening and implementation engagements between them.Incident response, containment and recoveryDelivering the containment and recovery phases of live client security incidents, including ransomware, business email compromise and perimeter device exploitation.Isolating affected systems and accounts, restricting compromised identities, closing off attacker access routes, and preventing further spread across the estate.Preserving logs and evidence for the forensic investigation team, and working alongside them as the investigation develops.Supporting client recovery, including rebuild and restoration sequencing driven by business priority, and ensuring known weaknesses are not reintroduced.Implementing the remediation and hardening work identified through the incident, where clients engage us to deliver it.Working to the NIST Cyber Security Framework and incident response lifecycle, with CIS Benchmarks used for technical control recommendations.Security assessment and hardeningPerforming security reviews and configuration hardening across Microsoft 365 and Entra ID, Microsoft Azure, Amazon Web Services, on-premise Active Directory, and perimeter firewall estates.Conducting firewall security assessments across multiple vendor platforms: rule base review, management plane exposure, VPN and remote access configuration, IPS/IDS posture, logging, and firmware currency.Assessing cloud configuration against CIS Benchmarks and NIST using tooling including Prowler, ScubaGear and PingCastle, and turning technical findings into prioritised, business-contextualised remediation plans.Reviewing third-party software, cloud applications and SaaS platforms as part of supplier and technology assurance work.Supporting client compliance and assurance requirements including GDPR, Cyber Essentials Plus and PCI DSS.Security solution design and implementationDesigning and implementing security solutions in client environments, from discovery and requirements gathering through build, testing, rollout and handover.Working as part of the delivery team on a Zero Trust access programme built on Netskope One SASE, covering Secure Web Gateway, CASB (inline and API), Private Access (ZTNA) and Data Loss Prevention, integrated with Microsoft Entra ID and endpoint management.Designing and deploying Microsoft 365 conditional access policy sets, including MFA enforcement, legacy authentication blocking, device compliance conditions, geolocation restriction, and Privileged Identity Management for just-in-time privileged access.Designing network segmentation across cloud and on-premise environments: Azure Network Security Groups and subnet-level control, VLAN segregation, DMZ isolation, and layer 2 / layer 3 access control.Designing data classification and DLP policy, working with client data and business process owners to define label sets and handling outcomes, and validating policy behaviour in simulation before enforcement.Producing security architecture artefacts, hardening standards, deployment guides, operating procedures and SOC playbooks so client teams can operate and extend what you have built.Knowing you’re right for usJoining us as an experienced Network Engineer, the minimum criteria you’ll need is a background in network engineering with demonstrable experience of applying it to security outcomes, ideally with 36 months in a security-focused role, together with the Netskope Certified Cloud Security Integrator (NCCSI), which you must be actively working towards if you do not already hold it. You should also be able to demonstrate the following during the interview process.Technical experienceNetworking: LAN/WAN, VLAN segmentation, layer 2 / layer 3 access control, routing and switching, DMZ architecture, DNS and DHCP. A background as a network engineer prior to moving into security.Network security: Cisco (including Firepower), Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel and F5. Firewall policy design and review, IPS/IDS, site-to-site and remote access VPN, and SSL/TLS inspection.SASE and Zero Trust: Netskope One, Secure Web Gateway, CASB, Private Access (ZTNA) and DLP. Client deployment, steering configuration, tenant configuration and troubleshooting.Cloud: Microsoft Azure (NSGs, Azure Firewall, Azure Policy, Defender for Cloud), Microsoft 365 and Entra ID (conditional access, PIM, Entra Connect), AWS and Oracle Cloud. Terraform for infrastructure as code.Endpoint and detection: CrowdStrike Falcon (EDR, NG-SIEM, LogScale).Identity: Active Directory, Entra ID, Group Policy, RBAC and privileged access.Frameworks: NIST CSF and NIST 800-53, CIS Benchmarks, and ISO 27001.Qualifications and certificationsYou will hold, or be actively working towards, the Netskope Certified Cloud Security Integrator (NCCSI). This is a minimum criterion for the role.Beyond this, you will hold, or be working towards, a relevant combination of the following:Cisco Certified Network Associate (CCNA)Cisco Certified Entry Networking Technician (CCENT)AWS Certified Cloud PractitionerMicrosoft Certified: Azure Fundamentals (AZ-900)Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900)Oracle Cloud Infrastructure Foundations AssociateMicrosoft Certified Technology Specialist (MCTS)ITIL Foundation v3Soft skillsCommunication: A clear and confident communicator with strong written and verbal skills, particularly in high-pressure scenarios. Able to translate technical detail for non-technical audiences, including clients, vendors and senior stakeholders.Analytical thinking: Able to analyse complex environments and data, identify patterns and make evidence-based decisions.Problem solving: Strong troubleshooting skills and the ability to develop solutions quickly and effectively during active incidents.Teamwork and collaboration: Comfortable working closely with DFIR, SOC, Cyber Advisory and client technical teams. Collaboration is essential during incident response.Adaptability: Able to embrace and manage change effectively, continuously developing skills to meet the demands of an evolving threat landscape.Time management: Able to prioritise effectively while managing multiple engagements and ensuring SLAs, KPIs and client deadlines are met.Attention to detail: Careful and precise when making changes in live client environments, with high-quality, accurate documentation of every action taken.#LI-SS1
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Defence Network Engineer
Cyber Defence Network Engineer

Grant Thornton UK LLP • Greater London

On-site
GBP 65,000 - 105,000
Cyber Defence Network Engineer
Cyber Defence Network Engineer

Grant Thornton (UK) • City Of London

On-site
GBP 65,000 - 95,000
Flexible working options
Collaborative, cross-functional team
Cyber Defence Network Engineer
Cyber Defence Network Engineer

ukgrantt • Greater London

On-site
GBP 60,000 - 85,000
Senior Network Security Engineer
Senior Network Security Engineer

ITC Secure • United Kingdom

On-site
GBP 40,000 - 60,000
25 days annual leave
Private health insurance
Enhanced maternity and paternity leave
+4
Senior IT Security Analyst
Senior IT Security Analyst

Cyber UK • Greater London

On-site
GBP 90,000 - 130,000
Hybrid working
Personal pension plan
Private medical & dental insurance
+1
Cyber Defence Network Engineer: Incident Response & Zero Trust
Cyber Defence Network Engineer: Incident Response & Zero Trust

ukgrantt • Greater London

On-site
GBP 60,000 - 85,000
Cyber Security Engineer
Cyber Security Engineer

Digital Waffle • Manchester

On-site
GBP 45,000 - 65,000
Senior Network Engineer – Cyber Engineer
Senior Network Engineer – Cyber Engineer

Cyber UK • Greater London

Hybrid
GBP 75,000 - 95,000
Hybrid work model
Bonus
On-call allowance
+2
Security Engineer
Security Engineer

GBV Ltd • Preston

On-site
GBP 54,000 - 66,000
Bonus
Benefits
Senior Network Security Engineer On site
Senior Network Security Engineer On site

ITC Secure • Greater London

On-site
GBP 70,000 - 90,000
25 days annual leave
Pension scheme
Private health insurance
+6