Get more replies from employers
Send a job-specific resume in minutes.
FTSE 100 in London is seeking a Cyber Security Platform Engineer – Microsoft to own the Microsoft security estate, drive E5 deployment, and align Defender, Entra ID, Intune, and Azure configurations with the Group security standard. You will partner with the Security Platform Engineering Manager to prioritise high-value work and minimise downtime.
The role requires strong collaboration with divisional IT teams, SOC, and Microsoft teams, plus hands-on configuration and change management across a
Title: Cyber Security Platform Engineer – Microsoft
Reference No: 2161
Company: FTSE 100
Reports to Security Platform Engineering Manager
Location: London
Working Pattern 37.5 hours per week, Monday – Friday. Location: London/Peterborough, with potential travel to divisional sites as required by advisory engagements (hybrid working arrangements in place).
Salary: £59,000 - £72,000
Benefits Bupa, Matched pension contributions.
The Role
The Group Cyber Security (GCS) team is responsible for managing cyber risk appropriately across) the Group and has recently refreshed its cyber strategy, with a renewed focus on embedding cyber security as part of the culture and DNA. This is a highly federated business model spanning 11 divisions and over 50 countries, and the cyber strategy has been designed to build materially improved security capabilities whilst working with a divisional focus.
It is an exciting time to join GCS. We are in a period of significant investment, with a multi-year transformation programme under way to build new security capabilities at pace. GCS is responsible for setting the Group cyber standard, measuring compliance against it across all the businesses, and delivering a portfolio of centrally managed security services that divisions can rely on.
The Security Platform Engineering function is central to that portfolio – responsible for ensuring that the security tools the organisation invests in are deeply understood, expertly configured, continuously improved, and consistently delivering their intended security and business value. Microsoft is the most strategically significant security platform, and the uplift and optimisation of the Microsoft security estate is one of the most consequential engineering challenges in the GCS transformation programme.
Role Summary
Reporting to the Security Platform Engineering Manager, the Cyber Security Platform Engineer – Microsoft is the Group dedicated technical authority for the Microsoft security platform. The role carries implied ownership of the full Microsoft security stack: the M365 Defender suite, the security-relevant capabilities of Microsoft Entra ID (conditional access, Privileged Identity Management, access packages, and least privilege), Intune, and the foundational configuration of the Microsoft 365 and Azure environments on which all of these depend. This is a role that extends beyond BAU platform management: a significant part of the initial mandate is to critically assess the current state of the Microsoft estate – spanning E3, Active Directory, Entra ID, Intune, and existing Defender deployments – identify the gaps against vendor-recommended best practice and the Group cyber standard, and build a prioritised strategy and plan to close them.
This role is the primary technical owner of that relationship on the GCS side – working directly with the Microsoft team to prioritise, plan, and drive the E5 deployment across the estate, and ensuring that the professional services and engineering resources available are directed at the highest-value activities. The role must navigate the realities of the federated organisation with skill: delivery will depend on partnership with divisional IT teams, and getting there will require excellent stakeholder management, a clear change communication approach, and an absolute commitment to end-user experience. Zero tolerance for avoidable downtime is not a preference – it is a non-negotiable operating constraint.
The role works in close partnership with the Cyber Architecture Manager, the Group CTO function, the IT Frameworks Director, Assurance leads, Divisional Security Leads, and the Identity Transformation team. It shares the defining mindset of the whole platform engineering function: genuine passion for the Microsoft platform, curiosity about its full capability, and the drive to get to a secure, consistent, vendor-recommended configuration as quickly and as safely as possible.
Role Responsibilities / Accountabilities
Microsoft Estate Assessment, Gap Analysis & Strategy
Conduct a structured, critical assessment of the current Microsoft security estate, covering Active Directory, Microsoft Entra ID, Intune, M365 (E3 and current Defender deployments), and Azure security configuration; benchmark the current state against Microsoft’s secure score recommendations, vendor best practice, and the Group cyber technical standard, and produce a clear, evidence-based gap analysis.
Microsoft Defender Platform Ownership & Engineering
Own the technical configuration, ongoing engineering, and operational health of the full M365 Defender suite, including Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365, and Microsoft Sentinel integration; maintain configurations to the approved baseline and drive continuous improvement against vendor-recommended configuration.
Entra ID Security & Identity Controls
Own the security configuration of Microsoft Entra ID across the Group; take implied technical ownership of the security-relevant Entra capabilities including Conditional Access policy design and enforcement, Privileged Identity Management (PIM), access packages and entitlement management, Identity Protection, and the application of least privilege principles across the directory.
E5 Migration, ECIF Engagement & Microsoft Relationship
Act as GCS’s primary technical liaison to the Microsoft ECIF (Engineering Co-Investment Fund) team; plan, prioritise, and drive the E5 deployment programme in partnership with the ECIF team, ensuring that Microsoft engineering resources are directed at the highest-value activities and that the Organisation is getting the maximum benefit from the co-investment engagement.
Divisional Engagement, Change Communication & End-User Focus
Work directly with Divisional Security Leads to share emerging practice, gather direct and usable feedback on how Microsoft security configurations are landing in the business, and drive adoption of a consistent, vendor-recommended Microsoft configuration across all 11 divisions as quickly as the operating model allows.
Put end users at the heart of every configuration and deployment decision; maintain a zero-tolerance approach to avoidable downtime, design changes to minimise disruption to business operations, and ensure that user-impacting changes are thoroughly tested and piloted before broad rollout.
Own the change communication approach for Microsoft platform changes; ensure that divisions, IT teams, and end users understand what is changing, why it is changing, and what they need to do – well in advance of any change taking effect; develop training and guidance materials that help users and IT teams adapt confidently to new security controls.
Provide technical configuration guidance and support to divisional IT and security teams deploying or operating Microsoft security platforms in their environments; act as the technical authority for Microsoft platform queries across the Group, and help divisional teams reach and maintain compliance with the Group Microsoft security baseline.
Identity Transformation Alignment & Stakeholder Collaboration
Work closely and continuously with the Identity Transformation team throughout the transformation programme; ensure that GCS Microsoft security configuration activity – particularly Entra ID, PIM, and Conditional Access – is aligned with and supportive of the broader identity transformation workstream, and that dependencies, conflicts, and sequencing decisions are surfaced and resolved early.
Collaborate with the Group CTO function and IT Frameworks Director to ensure that Microsoft security platform plans are integrated into the broader IT technology strategy; surface platform interdependencies that span security and non-security technology and ensure they are managed proactively.
Contribute actively to continuous improvement within the Security Platform Engineering function; document lessons learned from each phase of E5 delivery, share practice with other platform engineers, and help build the team’s collective Microsoft knowledge and capability over time.
Experience
Experience, Knowledge, Skills & Attributes Essential
Knowledge & Skills
Experience, Knowledge, Skills & Attributes Desirable
Qualifications
SC-100 (Microsoft Cybersecurity Architect) demonstrating breadth across the Microsoft security portfolio at the design and strategy level.
CISSP or CISM providing broader security leadership credentials alongside deep Microsoft specialism.
Microsoft Certified: Identity and Access Administrator Associate (SC-300) if not already held as an Essential requirement.