Up to £75,000 PA
Well-established and highly profitable construction engineering business is seeking an experienced SecOps Engineer to join them on a permanent basis. This is a critical role within an organisation undergoing significant digital transformation, with ambitious growth and acquisition plans driving the need for secure, scalable and standardised IT services.
This role is ideal for a proactive security professional with strong technical expertise across Microsoft 365, cloud, infrastructure and network security. You will play a key part in implementing security controls, mitigating risk, improving the organisation's overall security posture and ensuring systems remain compliant with ISO 27001 and Cyber Essentials Plus (CE+).
Responsibilities:
- Monitor security tools including SIEM (QRadar) and respond to threat detection alerts
- Triage, analyse and prioritise security incidents via ServiceNow
- Investigate root causes of security issues and design effective remediation solutions
- Oversee Patch Management across servers, endpoints and infrastructure
- Conduct vulnerability scans using Qualys, analyse findings and prioritise remediation activities
- Take ownership of the Microsoft 365 security platform, proactively analysing the environment and remediating security recommendations across Microsoft Defender, Entra ID and Intune
- Review, optimise and maintain Conditional Access Policies, Compliance Policies and Configuration Profiles to ensure user accounts and endpoint devices remain secure and compliant
- Implement and continuously improve Microsoft 365 security controls, identity protection and endpoint compliance in line with Microsoft best practices
- Support the organisation's ISO 27001 and Cyber Essentials Plus (CE+) compliance by implementing and maintaining appropriate Microsoft security controls
- Manage end-user device (EUD) security through Microsoft Intune, Sophos and NinjaOne
- Schedule and assess vulnerability scans on critical infrastructure
- Maintain patching compliance for Windows OS, Microsoft 365 applications and third-party software
- Collaborate with external SOC providers to investigate and respond to security incidents
- Automate security processes and operational tasks using PowerShell, Batch or similar scripting languages
- Produce post-incident reports, root cause analyses and security recommendations
- Document SecOps processes and create knowledge base articles in line with best practices
- Support infrastructure teams to deploy systems, strengthen security policies and manage security-related changes
- Produce weekly security operations and compliance reports
- Manage Cisco Umbrella web filtering and SSL inspection policies
Requirements:
- Previous hands-on experience within a Security Operations (SecOps), Cyber Security or Incident Response role
- Strong experience administering and securing Microsoft 365 environments
- Hands-on experience with Microsoft Entra ID, Microsoft Intune, Microsoft Defender and Microsoft 365 security capabilities
- Experience reviewing and optimising Conditional Access Policies, Compliance Policies and Configuration Profiles
- Experience assessing Microsoft Secure Score and remediating Microsoft 365 security recommendations
- Experience implementing Microsoft security controls to support ISO 27001 and Cyber Essentials Plus (CE+) compliance
- Strong knowledge of Microsoft Windows security and system hardening
- Working PowerShell scripting ability for automation tasks
- Solid understanding of cloud security across Microsoft 365, Azure and AWS
- Experience supporting enterprise IT infrastructure
- Recognised security certifications such as Security+, CEH, Microsoft Security certifications or equivalent
Any experience with the following will be highly favoured:
- Qualys Vulnerability Management
- QRadar SIEM
- Varonis
- Microsoft Purview (Compliance, Information Protection or Data Loss Prevention)
- ServiceNow
- Network security knowledge covering TCP/IP, VPNs, routing, firewalls and network segmentation
- Sophos security solutions
Initially 4 days per week onsite in Central London, reducing to 2 days per week after probation.