Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Weâre supporting a leading organisation operating within a highly regulated and nationally significant environment as they continue to build and mature a new Microsoft cloud security estate.
This is a hands-on Security Engineer position suited to someone who enjoys improving security posture, implementing controls and solving security challenges in an evolving environment. Youâll play a key role in strengthening the organisationâs cyber security capabilities while helping prepare the environment for an upcoming penetration test programme over the next 3-6 months.
The team are looking for someone who can work autonomously, identify potential weaknesses before they become audit or pen-test findings, and drive remediation activities from start to finish., * Implement, configure and maintain security controls across the Microsoft security ecosystem.
- Identify security gaps and drive remediation activities to improve overall security posture.
- Support the preparation, coordination and remediation of external penetration testing engagements.
- Implement and manage identity, access management and privileged access controls.
- Configure and maintain Conditional Access, RBAC and Privileged Identity Management controls.
- Improve device, identity, data and cloud security controls across the estate.
- Support audit, assurance and compliance activities.
- Work closely with architecture, security operations and wider technology teams to deliver security improvements.
- Contribute to security hardening initiatives and CIS control implementation., * Microsoft Security Engineer
- Identity & Access Management Engineer
- Azure Security Engineer
- Cyber Security Engineer
who enjoys hands-on technical delivery and taking ownership of security improvements within a developing environment.
Requirements
- Strong Security Engineering background.
- Hands-on experience with:
- Microsoft Entra ID
- Microsoft Intune
- Microsoft 365 Security
- Microsoft Azure
- Microsoft Purview
- Experience implementing and assessing CIS security controls.
- Previous experience remediating vulnerabilities and penetration testing findings.
- Strong understanding of:
- Identity & Access Management (IAM)
- RBAC
- Privileged Access Management
- Least Privilege principles
- Experience working in cloud-first Microsoft environments.
- Ability to work independently and proactively identify security improvements.
- Strong stakeholder engagement and communication skills.
Desirable Experience
- Experience preparing environments ahead of external penetration testing.
- Exposure to regulated, critical infrastructure or highly secure environments.
- Experience working alongside Security Operations or Incident Response teams.
- Microsoft or security certifications such as SC-200, SC-300, SC-400, AZ-500, CISSP or CCSP.
Benefits & conditions
| 6-Month Contract | ÂŁ700-ÂŁ800 per day (Umbrella)Hybrid Working | Midlands-based office visit approximately once per month |
About the company
Pontoon is an employment consultancy. We put expertise, energy, and enthusiasm into improving everyoneâs chance of being part of the workplace. We respect and appreciate people of all ethnicities, generations, religious beliefs, sexual orientations, gender identities and more. We do this by showcasing their talents, skills, and unique experience in an inclusive environment that helps them thrive.
We use generative AI tools to support our candidate screening process. This helps us ensure a fair, consistent, and efficient experience for all applicants. Rest assured, all final decisions are made by our hiring team, and your application will be reviewed with care and attention.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role â technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
Dev Digest 191: Malware interviews, EU â¤ď¸ Open Source and Skilled Agents