> Markdown version of [/jobs/ext/1327059-senior-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/1327059-senior-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Cyber Security Engineer - **Company:** The Beauty Tech Group - **Location:** Manchester, UK (Remote available) - **Experience:** Expert - **Salary:** £53,964.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Application Programming Interfaces (APIs), User Authentication, Software as a Service, Cyber Security, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Email Filtering, Federated Identity Management, Identity and Access Management, Network Security, Microsoft Software, Network Segmentation, OpenID, Performance Tuning, Role-Based Access Control, Phishing, Software Vulnerability Management, EndPointSecurity, Microsoft InTune, Sender Policy Framework (SPF), Malware Detection, Gsuite - **Published:** July 18, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5805061318 ## About the Role * Hands on experience administering and hardening the Microsoft stack Intune, * Defender for Endpoint and Entra ID as the core of a live endpoint and identity estate. * Strong working knowledge of modern identity and access management: authentication * protocols, conditional access, Entra app registrations and the Principle of Least * Privilege. * A track record of operating independently in a security or senior infrastructure role, * comfortable owning and driving work with minimal oversight. * A clear communicator who can explain technical reasoning to non-technical colleagues * and constructively challenge decisions, including upward. Desirable * Experience administering and hardening Google Workspace alongside Microsoft 365. * Familiarity with federated identity and modern authentication methods AML/OIDC, * Windows Hello for Business and macOS Platform SSO. * Working knowledge of email authentication SPF, DKIM and DMARC. * Experience working alongside an external MDR/SOC partner for detection and incident * response. * A grounding in network security fundamentals, segmentation, wireless * authentication and secure access ideally on Cisco Meraki. * Hands on experience with vulnerability management tooling and patch/remediation * workflows. * Awareness of security governance and compliance evidence work, such as supporting * audit and disclosure obligations. * Relevant certifications (e.g. Microsoft SC-200, SC-300 or AZ-500, or equivalent) ## Description We are looking for an experienced, hands-on Senior Cyber Security Engineer to take technical ownership of our security tooling and controls the first dedicated cyber security hire in a growing in house IT and Security function. Reporting directly to the Head of IT & Security, this is a high autonomy role with a genuine voice in shaping our security strategy: not executing someone else's playbook, but helping to write it. You will own the configuration, hardening and continuous improvement of our defensive stack across a modern Microsoft and Google estate, working hands on day to day while partnering with the wider business to keep a fast-growing, global organisation secure and resilient. As the function matures, there is a clear path for the right person to grow the role and, in time, a team around them. What you'll be doing Security Operations & Tooling Ownership * Endpoint & Device Strategy: Own the technical configuration, lifecycle management * and policy optimisation of endpoint security tooling and enterprise mobile device * management (MDM/MAM), namely Microsoft Intune and Defender. * Identity & Access Management: Harden and manage Identity & Access Management * (IAM) baselines across our core collaboration ecosystems (including Microsoft 365 and * Google Workspace), ensuring strict adherence to the Principle of Least Privilege. * Authentication & Email Hardening: Optimise modern authentication types (Windows * Hello, macOS Platform SSO), secure application API permissions and Entra Enterprise * App Registrations, and advance our email filtering policies ensuring our SPF, DKIM * and DMARC records are correctly provisioned and optimal. * Network Foundations: Support network security objectives, contributing technical * oversight to core networking principles, network segmentation, wireless * authentication and secure access pathways. Incident Response & Vulnerability Execution * Threat Mitigation: Act as the primary internal technical interface for our Managed * Detection and Response (MDR) platform, coordinating rapid threat isolation, host * containment and system tuning. * Vulnerability Lifecycle: Deploy and manage vulnerability management tooling, taking * ownership of patch remediation, configuration audits and threat tracking across the * estate to systematically close technical blind spots. * Resilience Planning: Assist in the design, technical testing and documentation of * operational incident response playbooks and isolated system backup verification * procedures. * Continuous Tuning: Maintain and optimise anti-malware and filtering controls so that * security standards balance effectively against user productivity. Governance, Continuity & Collaboration * Change Control: Adhere to and champion strict internal change control processes so * that security enhancements and maintenance do not disrupt operational continuity. * Security by Design: Partner with wider business units to conduct lightweight security * and technical risk assessments on new third-party SaaS vendors and systems prior to * onboarding. * Compliance Telemetry: Support the Head of IT & Security with evidence gathering, * audit tracking and data telemetry to validate our ongoing cyber resilience and * company disclosure obligations. * Security Culture: Promote a culture of accountability and security awareness, * including the coordination and technical execution of data driven internal phishing * simulation exercises. ## Related Videos - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) - [Going Beyond Passwords: The Future of User Authentication](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs)