An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Kocho is seeking an experienced Security Engineer to protect client environments and lead Microsoft Defender XDR initiatives. You will design, implement, and optimise security measures across systems and data, working with clients and the Security Operations team to ensure ongoing compliance and improvement.
You will deliver hands-on expertise across the Microsoft Security Stack, develop detection capabilities with KQL, and drive vulnerability management, reporting, and remediation with guidance
We are Kocho
Kocho is the original Microsoft identity-centric security partner, delivering transformational services for UK organisations. We secure every identity first - then use that foundation to strengthen security, modernise cloud and apps, and keep everything running through leading managed services, and managed security operations.
You’ll be joining a team that’s trusted by organisations to deliver at scale. As an eight-time Microsoft Partner of the Year winner and one Microsoft's most decorated UK partners.
Our work speaks for itself:
Our head office is in the heart of London, with additional offices in Cardiff and Cape Town, providing a comfortable working environment with flexible collaboration spaces. And we're guided by our core values: Do What's Right, Think Greater, and Better Together.
Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences We consider all suitable candidates regardless of their age, sex, gender reassignment, race, pregnancy and maternity, religion or belief, marital status, disability or sexual orientation. This is mindset aligns with our company values as we understand that we are Better Together.
As a Security Engineer, you will play a critical role in safeguarding our organisation, clients, and partners from cyber threats. You will apply your experience in Security Engineering or as a Senior Security Analyst to design, implement, and optimise security measures that protect systems, networks, and data from unauthorised access, attacks, and breaches. Working closely within the Security Operations team and directly with clients, you will ensure that security controls remain effective, aligned to best practice, and continuously improved. This role is primarily remote but you may be asked to come into the Cardiff or London Office at your manager's discretion, we would expect a successful candidate to always attend when required. We anticipate this to be a couple times a month. In this role, you will deliver hands‑on expertise across the Microsoft Security Stack, particularly Microsoft Defender XDR and Microsoft Sentinel. You will build, maintain, and enhance detection capabilities by deploying KQL analytical rules, developing Content Hub solutions, and tuning threat policies to ensure strong protection and high‑quality signal. Your responsibilities will include managing phishing simulation campaigns, leading vulnerability scans, and producing accurate, well‑structured reports with clear, actionable recommendations. You will regularly engage with clients, presenting findings and guiding them through remediation activities alongside a Cyber Security Project Manager. You will also provide Incident Response support by handling escalations from the triage team, performing advanced investigations, and contributing to playbook automation using Azure Logic Apps to streamline processes and improve response consistency. Your Incident Response involvement is only from an Escalation Standpoint and you are not expected to regularly be involved in Analyst related activities. Additionally, you will audit and uplift client environments across the Microsoft 365 Security Suite, focusing on areas such as Secure Score improvements, Device Tagging, Defender policy management, Exchange configuration hardening, and other lifecycle‑related security tasks. Where applicable, you may also leverage scripting or automation skills (e.g., Python, Bicep, ARM, JSON, YAML) and contribute to Logic Apps, Azure Functions, or codeless playbooks to further enhance operational efficiencies.