> Markdown version of [/jobs/ext/2856689-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/2856689-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Sword Group - **Location:** Aberdeen, UK - **Experience:** Expert - **Salary:** £49,279.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Microsoft Antivirus, Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Internet Security, Microsoft Security Essentials, Microsoft Office, Azure Active Directory, Cloud Services, Phishing, Kusto Query Language, Security Information and Event Management, Software Deployment, Software Vulnerability Management, Microsoft Power Automate, Software Security, Microsoft InTune, Microsoft Sentinel - **Published:** September 12, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5879885871 ## About the Role We are looking for a Cyber Security Engineer to join our security team and take the lead on our security operations. Reporting to the Group CISO and working closely with IT, you will take ownership of the day-to-day running of Sword's technical security controls, with a strong focus on Microsoft security technologies. You will play a leading role in strengthening monitoring, detection, protection, and response across the business, and in automating the work that should not be done by hand. This role suits someone with at least five years of hands-on experience, a positive can-do attitude, and the ability to take ownership, work autonomously, manage workload effectively, and deliver results. This is a hands-on technical role with real ownership, focused on implementing, operating, and improving security controls across Sword's environment. Working with IT and the wider security function, you will strengthen monitoring, protection, detection, response, and technical assurance through effective use of security technologies and services, and you will look for opportunities to automate. We are looking for someone who is proactive, practical, and delivery-focused, with the confidence to work independently, agree and manage priorities, and follow through with minimal supervision., You will need to be able to demonstrate technical experience in cyber security engineering or security operations, including direct responsibility for the day-to-day running of security tooling and incident response. Attitude matters greatly. We are looking for someone who delivers results and brings a positive, practical approach to solving problems. You should have hands-on experience in most of the following areas, and we may explore some of them practically during the interview process: * Microsoft security technologies, in depth. Microsoft Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint detection and response. * Automation. Practical experience of removing manual effort from security operations using scripting, playbooks, Logic Apps, APIs, or similar. You should be able to talk about something you automated, what it replaced, and what it saved. * Security control operation. Operating and improving security controls across areas such as endpoint protection, SIEM, vulnerability management, identity and access management, data protection, email security, cloud security posture, and system hardening., * Background. Experience gained in a complex business environment, working with internal teams and external providers, ideally including a managed service or multi-client setting., * Relevant technical certifications are desirable, particularly in Microsoft security technologies such as SC-200, SC-300, SC-400, AZ-500, or similar. * Broader security certifications are welcomed but not essential if you can demonstrate strong hands-on technical capability. * Takes ownership, works independently when needed, and stays focused on delivering high-quality outcomes. * Curious, proactive, and comfortable working out what needs doing rather than waiting to be asked. * Able to manage workload effectively, prioritise sensibly, and maintain momentum in a busy technical environment. * Communicates clearly and works well with technical and non-technical colleagues to turn security requirements into practical actions and improvements. * Makes good use of tooling and automation to get more done, and is always looking for a better way to handle routine work. * Keeps pace with the threat landscape out of habit rather than obligation, forms a view on what new threats and techniques mean for an organisation like ours, and raises them proactively. ## Description * Security Monitoring and Operations - Own the day-to-day security operations across Microsoft security technologies including Microsoft Sentinel, Microsoft Defender, Conditional Access, Entra ID, and related Azure security capabilities, strengthening monitoring, detection, protection, and response. You will help shape what effective monitoring looks like at Sword, working in partnership with the CISO and the wider IT team. * Vulnerability Management and Hardening - Proactive and risk-based vulnerability management, including attack surface reduction, system hardening, remediation support, and cloud security posture improvement. You will also coordinate penetration testing and security assessments, and drive the findings through to remediation. * Automation and Continuous Improvement - Reduce manual effort across security operations through automation, scripting, and integration. Where work is repetitive, look to automate it. Identify and implement improvements to security tooling, detection logic, control effectiveness, and operational processes through tuning, automation, and incremental engineering. This is an important part of the role. * Security Tooling and Services - Own the security tooling estate and work closely with our external providers to make sure the services we buy deliver the outcomes we need, resolving technical issues and improving day-to-day security outcomes. * Incident Investigation and Response - Own and run security incidents from start to finish, covering technical investigation and triage, containment, remediation, closure, and keeping the business informed as it unfolds. We are looking for someone who has personally led incidents rather than taken part in them as one of a wider team, and who turns each one into a lasting improvement in our detection and response. * Security Awareness and Enablement - Provide the technical input behind awareness activity, simulated phishing exercises, and secure working practices, helping colleagues work safely without adding friction to their day. * Technical Compliance and Assurance - Own the technical controls behind our certifications and assurance activity, including Cyber Essentials Plus, ISO 27001, evidence gathering, and remediation. * Technical Risk Assessment - Lead technical security risk assessment across projects, suppliers, and internal services, identify where we are exposed, and drive practical remediation and hardening. * Regulatory and Client Requirements - Implement, maintain, and evidence the technical controls we need to meet relevant legal, regulatory, and client security obligations. * Supplier and Integration Security - Lead technical reviews of supplier and partner services, integrations, and access arrangements, and make sure the right controls are in place and stay in place. This is an excellent opportunity to work with a talented team across modern security technologies, and to make a meaningful contribution to strengthening Sword's cyber security capability. If you enjoy solving technical security challenges and want the scope to own and improve how security operations runs, we would like to hear from you., * Frameworks and standards. Applying security frameworks, standards, and regulatory drivers such as NIST, ISO 27001, GDPR, and NIS2 through practical technical controls. * Cyber Essentials Plus. Technical control implementation, evidence collection, remediation tracking, and preparation for assessment. * Secure deployment. Supporting the secure configuration and deployment of applications, infrastructure, identities, and cloud services, working with IT teams to embed appropriate controls without slowing delivery. * Communication. Comfortable at both ends of the conversation: technical enough to work directly with our security operations centre on detections and incidents, and clear enough to explain to senior stakeholders, up to and including the CEO, what has happened, what it means, and what we are doing about it. You will also provide practical guidance to colleagues and technical input to awareness, audit, and assurance activities., At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don't tick all the boxes but feel you have some of the relevant skills and experience we're looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)