> Markdown version of [/jobs/ext/2820757-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/2820757-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Sanderson Recruitment Plc - **Location:** London, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Domain Controllers, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Continuous Integration, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Log Analysis, Windows Servers, PCI Data Security Standards, Public Key Infrastructure, Role-Based Access Control, Azure Active Directory, Cloud Services, Zero Trust Network Access, Runbook, Security Information and Event Management, Software Vulnerability Management, Software Security, Bicep, Microsoft Sentinel, Hardware Infrastructure, Terraform, Network Server, Devsecops, Key Vault - **Published:** September 10, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840600771-senior-security-engineer ## About the Role * Deep knowledge of Microsoft Entra ID, Active Directory, MFA, Conditional Access, PIM, and RBAC * Experience with SIEM/SOAR, EDR, CSPM, and vulnerability management tools * Practical experience securing Windows Server, domain controllers, PKI/ADCS, and hybrid identity * Solid understanding of Zero Trust and secure-by-design architecture * Working knowledge of PCI DSS, ISO 27001, Cyber Essentials Plus, and NIST * Strong investigation, log analysis, and incident response skills * AWS security fundamentals (IAM, GuardDuty, Security Hub, KMS) * DevSecOps or CI/CD security practices * Infrastructure-as-Code security (Terraform, Bicep) ## Description We are looking for a Security Engineer to design, implement, and operate security controls across a hybrid environment spanning Microsoft Azure, on-prem infrastructure, SaaS platforms, and a large UK retail footprint. This is a hands-on technical role with architectural influence, focused on identity security, cloud security posture, threat detection, endpoint and server hardening, data protection, and compliance. You'll work closely with Network Engineering, Infrastructure, Cloud, and Application teams to ensure security is embedded by design across the organisation. * London Based, * Define and maintain security baselines aligned to Microsoft, CIS, NIST, and Zero Trust principles * Govern cloud security using Azure Policy and Defender for Cloud * Provide security requirements and oversight for identity and access management, implemented by IAM teams * Own and operate SIEM, SOAR, and detection tooling (Microsoft Sentinel, Defender XDR) * Investigate and support incident response across identity, endpoints, servers, and cloud workloads * Implement and oversee endpoint and server security (hardening, EDR, vulnerability remediation) * Operate data protection controls including encryption, Key Vault, PKI, DLP, and sensitivity labels * Support compliance and audit activities (ISO 27001, PCI DSS, Cyber Essentials Plus, NIST) * Produce security documentation, runbooks, and audit artefacts * Collaborate closely with Network Engineering on segmentation, firewall governance, and secure connectivity * Provide security guidance across projects, platform changes, and operational teams ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Back(end) to the Future: Embracing the continuous Evolution of Infrastructure and Code](https://www.wearedevelopers.com/videos/440-back-end-to-the-future-embracing-the-continuous-evolution-of-infrastructure-and-code) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)