Cyber Security Engineer

Broaden

Greater London

On-site

GBP 75,000 - 95,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Hybrid work in London

Job summary

Broaden is seeking a Cyber Security Engineer to own the Zero Trust platform, Entra ID identity controls, and automated security governance from London (Hybrid). The role focuses on proactive engineering, not just policy oversight, with hands-on work across Defender XDR, Purview, and cloud security controls.

You will drive automation, evidence gathering, and onboard new entities using a structured containment approach, reporting to the Lead Infrastructure Security Engineer in a fast-scaling

Qualifications

  • Hands-on experience in security engineering, infra security or cloud security.
  • Experience in multi-tenant or acquisition-led environments.
  • Experience working with external security partners (MDR/XDR, vulnerability scanning) and SLAs.
  • Active SC-200, SC-300, or AZ-500 certifications are valued evidence of depth.

Responsibilities

  • Design and maintain identity and access controls across Entra ID estate, including CA policies and PIM.
  • Automate security tasks using PowerShell, Graph, and Logic Apps.
  • Tune and coordinate Defender XDR and Defender for Cloud with MDR provider to close gaps.
  • Define endpoint hardening baselines and Purview DLP policies across the estate.
  • Investigate alerts and perform proactive threat hunting with KQL and Sentinel.
  • Oversee vulnerability scanning and remediation within SLA, reviewing triage decisions.
  • Lead security onboarding playbooks for new acquisitions to standardize posture.
  • Build evidence pipelines for ISO 27001 and NIST CSF from tooling output.
  • Translate security risks into remediation steps for stakeholders.

Skills

PowerShell
Microsoft Graph
Logic Apps
KQL
Sentinel
Entra ID governance
Conditional Access
PIM
Defender XDR
Azure Functions

Tools

Defender for Cloud
Terraform
Bicep

Job description

Cyber Security Engineer | Zero Trust Platform & Identity Controls | Scale-Up Global Insurance Group | London (Hybrid) | £75-95K base DOE
About the Company

Our client is a fast-scaling, PE-backed specialist insurance group operating across the UK, Ireland, Europe, Singapore, and Australia. Having acquired over fifty separate businesses spanning specialist lines including professional indemnity, financial lines, and commercial insurance, they are executing a group-wide IT transformation programme to rebuild a fragmented legacy footprint into a unified, highly secure, and automated platform.

Operating with a Microsoft-first technology strategy, the organisation runs a lean in-house technology team that leverages world-class external partners to achieve massive operational leverage. They champion absolute ownership, engineering discipline, and radical simplicity—moving dynamically without layers of bureaucracy or corporate hand-holding. They are anti-bureaucracy but pro-governance, delivering regulatory compliance and security controls (ISO 27001 / NIST CSF) directly through platform automation rather than paperwork and committees.

If you are an exceptionally bright, technically curious engineer who would rather design a smart automated fix for a recurring problem than quietly work around it, you will find a massive opportunity here.

About the Role

Reporting directly to the Lead Infrastructure Security Engineer within the Security & Devices team, this is a hands-on, keyboard-level security engineering role designed to build, automate, and maintain the technical security controls protecting the group.

This is not a passive policy oversight or ticket-monitoring position. While you will provide second-line security operations cover for alerts escalated by the group's outsourced MDR/XDR provider, your primary mission is proactive security engineering. You will own the Zero Trust security programme covering Entra ID identity controls, Microsoft Defender XDR policy tuning, Purview data protection, and endpoint hardening standards implemented by the infrastructure team. Additionally, you will play a central role in the M&A security playbook—standardising and automating the security posture of newly acquired entities through a structured "Contain, Encapsulate, Absorb" methodology.

Key Responsibilities
  • Design, implement, and maintain identity and access controls across the group’s Entra ID estate, including Conditional Access policies, Privileged Identity Management (PIM), break-glass provisions, and authentication methods.
  • Treat security as an engineering discipline - automating recurring security tasks, evidence gathering, and access hygiene using PowerShell, Microsoft Graph, and Logic Apps in preference to manual workarounds.
  • Configure and tune protection, detection, and response policies across Microsoft Defender XDR and Defender for Cloud, partnering with the MDR provider to eliminate false positives and close coverage gaps.
  • Define endpoint hardening baselines for Windows and macOS (verified against deployed infrastructure) and enforce Microsoft Purview DLP and sensitivity labeling policies across the estate.
  • Perform second-line investigations of alerts escalated by the MDR provider across Defender XDR and Sentinel, conducting proactive threat hunting via KQL queries and Sentinel workbooks.
  • Oversee the outsourced vulnerability scanning service, driving findings through to remediation within SLA limits while quality-checking triage decisions and provider KPI performance.
  • Act as the technical security point of contact for newly acquired entities, executing the security onboarding playbook to remediate configuration gaps during integration.
  • Build and maintain technical evidence pipelines supporting ISO 27001 and NIST CSF frameworks, generating compliance documentation directly from tooling rather than assembling it by hand.
  • Hands-on experience configuring, tuning, and investigating alerts across Microsoft Defender XDR, Microsoft Sentinel, and Microsoft Defender for Cloud.
  • Strong technical grasp of Entra ID governance, including Conditional Access, PIM, and managing workload identity risks (service principals, app registrations, consent grants).
  • Proven ability to automate security operations using PowerShell and Microsoft Graph as a minimum, with ideal exposure to Logic Apps or Azure Functions.
  • Proficiency in writing KQL queries and leveraging Sentinel workbooks to establish incident scope, impact, and root cause.
  • Clear written and verbal communication, with the ability to translate technical security risks into clear remediation steps for non-technical stakeholders and infrastructure peers.
Qualifications & Experience
  • Demonstrable hands-on experience in a security engineering, infrastructure security, or cloud security role.
  • Experience working within multi-tenant, multi-entity, or acquisition-led environments.
  • Track record of working alongside or managing external security partners (MDR/XDR, vulnerability scanning), enforcing SLAs and escalation pathways.
  • Active SC-200, SC-300, or AZ-500 certifications are treated as evidence of technical depth and curiosity, never as a strict barrier to apply.
  • Exposure to Infrastructure-as-Code approaches (Bicep, Terraform) or Microsoft Defender for Cloud (CSPM/CWPP).
  • Employment Type: Permanent
  • Location: London (Hybrid – 2 to 3 days per week on-site)
  • Reporting Line: Lead Infrastructure Security Engineer
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Sanderson • Greater London

On-site
GBP 70,000 - 90,000
Security Engineer
Security Engineer

Burns Sheehan • Greater London

Hybrid
GBP 75,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Marks Sattin • England

On-site
GBP 60,000 - 80,000
Cyber Platform Engineer
Cyber Platform Engineer

ISS • Greater London

Hybrid
GBP 59,000 - 72,000
Bupa
Matched pension contributions
Security Engineer
Security Engineer

Areti Group | B Corp™ • City Of London

Hybrid
GBP 65,000 - 90,000
Senior Security Engineer
Senior Security Engineer

Eligo Recruitment • Greater London

On-site
GBP 56,000 - 96,000
Cyber Engineer
Cyber Engineer

IntaPeople Limited • West of England

Hybrid
GBP 72,000 - 88,000
Hybrid / remote working
Cyber Security Engineer
Cyber Security Engineer

IT Naturally • Peterborough

Hybrid
GBP 40,000 - 50,000
Private healthcare from day one
Company bonus
Pension
+4
Security Engineer
Security Engineer

GBV Ltd • Preston

On-site
GBP 54,000 - 66,000
Bonus
Benefits
Cyber Security Engineer
Cyber Security Engineer

Yolk Recruitment Ltd • Cardiff

Hybrid
GBP 62,000 - 72,000
Discretionary bonus up to 10%
25 days annual leave + bank holidays
Pension with Aviva: 5% employee, 10%+5
+7