Senior Cyber Security Engineer

The Beauty Tech Group Trading Limited

Manchester

Hybrid

GBP 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

25 days holiday
Pension scheme
WFH Wednesdays
On-site facilities
Staff discounts
Travel subsidies
Study support
Career development

Job summary

The Beauty Tech Group is seeking an experienced Senior Cyber Security Engineer to take technical ownership of our security tooling and controls within a growing in-house IT and Security function.

You will own the configuration, hardening, and continuous improvement of our defensive stack across a modern Microsoft and Google estate, working hands-on while partnering with the business to keep a fast-growing global organisation secure and resilient.

Qualifications

  • Hands-on experience administering and hardening the Microsoft stack Intune, Defender for Endpoint and Entra ID as the core of a live endpoint and identity estate.
  • Strong working knowledge of modern identity and access management: authentication protocols, conditional access, Entra app registrations and the Principle of Least Privilege.
  • A track record of operating independently in a security or senior infrastructure role, comfortable owning and driving work with minimal oversight.
  • A clear communicator who can explain technical reasoning to non-technical colleagues and constructively challenge decisions, including upward.

Responsibilities

  • Own the configuration, hardening and continuous improvement of our defensive stack across Microsoft and Google estates.
  • Act as primary internal technical interface for MDR platform, coordinating rapid threat isolation and system tuning.
  • Deploy and manage vulnerability management tooling, patch remediation and audits to close technical blind spots.
  • Design, test and document incident response playbooks and backup verification procedures.
  • Support change control and security risk assessments for new SaaS vendors and systems.

Skills

Intune
Defender for Endpoint
Entra ID
Identity & Access Management
Least Privilege
Independent Worker
Effective communicator

Tools

Google Workspace
Microsoft 365
MDR/SOC tooling
Cisco Meraki
Vulnerability management tooling

Job description

We are looking for an experienced, hands‑on Senior Cyber Security Engineer to take technical ownership of our security tooling and controls in a growing in‑house IT and Security function.

Reporting directly to the Head of IT & Security, this is a high‑autonomy role with a genuine voice in shaping our security strategy: not executing someone else’s playbook, but helping to write it.

You will own the configuration, hardening and continuous improvement of our defensive stack across a modern Microsoft and Google estate, working hands‑on day to day while partnering with the wider business to keep a fast‑growing, global organisation secure and resilient. As the function matures, there is a clear path for the right person to grow the role and, in time, a team around them.

What you’ll be doing
Security Operations & Tooling Ownership
  • Endpoint & Device Strategy: Own the technical configuration, lifecycle management and policy optimisation of endpoint security tooling and enterprise mobile device management (MDM/MAM), namely Microsoft Intune and Defender.
  • Identity & Access Management: Harden and manage IAM baselines across our core collaboration ecosystems (including Microsoft 365 and Google Workspace), ensuring strict adherence to the Principle of Least Privilege.
  • Authentication & Email Hardening: Optimise modern authentication types (Windows Hello, macOS Platform SSO), secure application API permissions and Entra Enterprise App Registrations, and advance our email filtering policies ensuring our SPF, DKIM and DMARC records are correctly provisioned and optimal.
  • Network Foundations: Support network security objectives, contributing technical oversight to core networking principles, network segmentation, wireless authentication and secure access pathways.
Incident Response & Vulnerability Execution
  • Threat Mitigation: Act as the primary internal technical interface for our Managed Detection and Response (MDR) platform, coordinating rapid threat isolation, host containment and system tuning.
  • Vulnerability Lifecycle: Deploy and manage vulnerability management tooling, taking ownership of patch remediation, configuration audits and threat tracking across the estate to systematically close technical blind spots.
  • Resilience Planning: Assist in the design, technical testing and documentation of operational incident response playbooks and isolated system backup verification procedures.
  • Continuous Tuning: Maintain and optimise anti‑malware and filtering controls so that security standards balance effectively against user productivity.
Governance, Continuity & Collaboration
  • Change Control: Adhere to and champion strict internal change control processes so that security enhancements and maintenance do not disrupt operational continuity.
  • Security by Design: Partner with wider business units to conduct lightweight security and technical risk assessments on new third‑party SaaS vendors and systems prior to onboarding.
  • Compliance Telemetry: Support the Head of IT & Security with evidence gathering, audit tracking and data telemetry to validate our ongoing cyber resilience and company disclosure obligations.
  • Security Culture: Promote a culture of accountability and security awareness, including the coordination and technical execution of data‑driven internal phishing simulation exercises.
Skills, knowledge & expertise
Essential
  • Hands‑on experience administering and hardening the Microsoft stack Intune, Defender for Endpoint and Entra ID as the core of a live endpoint and identity estate.
  • Strong working knowledge of modern identity and access management: authentication protocols, conditional access, Entra app registrations and the Principle of Least Privilege.
  • A track record of operating independently in a security or senior infrastructure role, comfortable owning and driving work with minimal oversight.
  • A clear communicator who can explain technical reasoning to non‑technical colleagues and constructively challenge decisions, including upward.
Desirable
  • Experience administering and hardening Google Workspace alongside Microsoft 365.
  • Familiarity with federated identity and modern authentication methods AML/OIDC, Windows Hello for Business and macOS Platform SSO.
  • Working knowledge of email authentication SPF, DKIM and DMARC.
  • Experience working alongside an external MDR/SOC partner for detection and incident response.
  • A grounding in network security fundamentals, segmentation, wireless authentication and secure access ideally on Cisco Meraki.
  • Hands‑on experience with vulnerability management tooling and patch/remediation workflows.
  • Awareness of security governance and compliance evidence work, such as supporting audit and disclosure obligations.
  • Relevant certifications (e.g. Microsoft SC‑200, SC‑300 or AZ‑500, or equivalent).
What's in it for you
  • 25 days holiday (increasing with service) + Holiday Buy scheme
  • Auto‑enrolment pension scheme
  • Work from home every Wednesday
  • On‑site café, gym and free parking
  • Staff discounts across CurrentBody Skin, ZIIP Beauty, and Tria Laser
  • Subsidised travel, Cycle to Work, and EV/tech schemes
  • Supported studies, Employee Assistance Programme and enhanced family leave
  • Social events, office brunches and career development opportunities

At The Beauty Tech Group, we are committed to creating a diverse and inclusive workplace where everyone feels valued and empowered to succeed. We welcome applications from all backgrounds and experiences.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Head of Cyber Security and Productivity Solutions
Head of Cyber Security and Productivity Solutions

M+C Saatchi UK • Greater London

On-site
GBP 120,000 - 180,000
Cultural stimulation allowance – £250 per person per year
Half days off before bank holidays
Emergency care days for dependants
+5
Lead Cyber Security Engineer
Lead Cyber Security Engineer

SThree • Glasgow

Hybrid
GBP 60,000 - 85,000
Hybrid working model
28 days holiday allowance
Private healthcare
Senior Cyber Security Engineer — Endpoint & IAM Leader
Senior Cyber Security Engineer — Endpoint & IAM Leader

The Beauty Tech Group Trading Limited • Manchester

Hybrid
GBP 90,000 - 130,000
25 days holiday
Pension scheme
WFH Wednesdays
+5
Cyber Security Manager
Cyber Security Manager

Dains Accountants & Advisers • Birmingham

Hybrid
GBP 50,000 - 70,000
Flexible and hybrid/smart working options
25 days annual leave
Health Insurance
+1
Senior Security Engineer
Senior Security Engineer

NCC Group • Greater Manchester

On-site
GBP 80,000 - 105,000
Flexible working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+4
Senior Security Engineer
Senior Security Engineer

NCC Group • Manchester

On-site
GBP 65,000 - 95,000
Flexible Working
25 days holiday plus bank holidays
Pension and Life Assurance
+4
Senior Application Security Engineer
Senior Application Security Engineer

Our Future Health Limited • Greater London

Hybrid
GBP 63,000 - 77,000
Generous Pension Scheme
30 Days Holiday
Enhanced Parental Leave
+4
Senior Security Engineer
Senior Security Engineer

NCC Group plc • Manchester

On-site
GBP 90,000 - 120,000
Flexible Working
25 days holiday + bank holidays
Medicash & Critical Illness Scheme
+7
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Jobtailor • Manchester

On-site
GBP 70,000 - 100,000
Cyber Security Manager
Cyber Security Manager

Which? • Greater London

Hybrid
GBP 73,000 - 80,000
Hybrid work
Health insurance
Pension 6-11%
+3