Security Engineer – Azure & Identity Security
We’re looking for an experienced Security Engineer to join a growing technology and security function within a fast‑paced, customer‑focused organisation. This is a hands‑on technical role with real architectural influence. You’ll help design, implement, and operate security controls across a complex hybrid environment spanning Microsoft Azure, corporate offices, datacentres, SaaS platforms, and a large UK retail footprint.
Working closely with Cloud, Infrastructure, Network Engineering, IAM, and Application teams, you’ll play a key role in strengthening security across cloud platforms, identity, endpoints, servers, data protection, threat detection, vulnerability management, and compliance.
As Security Engineer, you will take ownership of key security controls across cloud and on‑premises environments. You’ll define security standards, improve detection capabilities, strengthen identity and access controls, harden platforms, support incident response, and help ensure security is embedded into technology projects from the outset. You’ll work particularly closely with Network Engineering and Infrastructure teams, defining security requirements, reviewing configurations, and ensuring Zero Trust, least privilege, and compliance principles are consistently applied.
Key Responsibilities
- Design and implement security controls across Microsoft Azure, on‑premises infrastructure, endpoints, and SaaS applications.
- Define and maintain security baselines and hardening standards aligned with CIS, NIST, and Microsoft security benchmarks.
- Govern and enhance Azure security controls using Azure Policy, Microsoft Defender for Cloud, and cloud‑native security tooling.
- Strengthen identity security across Microsoft Entra ID and Active Directory, including Conditional Access, MFA, SSO, passwordless authentication, PIM, RBAC, and identity governance.
- Monitor and investigate identity threats, risky sign‑ins, compromised accounts, endpoint attacks, Azure security events, and server‑related incidents.
- Own and operate security monitoring and detection tooling, including Microsoft Sentinel, Defender XDR, Defender for Endpoint, and Identity Protection.
- Develop and improve SIEM detection rules, correlation logic, behavioural analytics, threat‑hunting use cases, and security automation.
- Support incident response, forensic investigation, root cause analysis, and post‑incident security improvements.
- Implement security hardening across Windows Server, domain controllers, Azure virtual machines, and virtualization platforms.
- Partner with Infrastructure teams on vulnerability management, patch governance, remediation, and secure configuration management.
- Support data protection controls including Azure Key Vault, PKI and certificate lifecycle management, Microsoft Purview, sensitivity labels, retention policies, encryption, and DLP.
- Strengthen Azure cloud security across Landing Zones, subscriptions, resource groups, workloads, Private Endpoints, Service Endpoints, and segmentation boundaries.
- Support compliance and audit activities across ISO 27001, PCI DSS, Cyber Essentials Plus, GDPR, and NIST frameworks.
- Participate in architecture reviews, threat modelling, risk assessments, penetration‑test remediation, change governance, and DR/BCP planning.
What We’re Looking For
- Strong Azure security experience, including Defender for Cloud, Azure Policy, Conditional Access, and identity protection tooling.
- Deep knowledge of Microsoft Entra ID, Active Directory Domain Services, MFA, PIM, RBAC, and hybrid identity security.
- Hands‑on experience with Microsoft Sentinel or similar SIEM platforms, SOAR, EDR, CSPM, and vulnerability management tooling.
- Experience securing Windows Server, domain controllers, PKI/AD CS, virtual machines, and virtualization environments.
- Strong understanding of Zero Trust and secure‑by‑design principles.
- Experience working with security frameworks and standards including PCI DSS, ISO 27001, Cyber Essentials Plus, and NIST.
- Strong incident investigation, threat triage, and log‑analysis skills.
#J-18808-Ljbffr…
