> Markdown version of [/jobs/ext/3288270-cyber-defence-network-engineer](https://www.wearedevelopers.com/jobs/ext/3288270-cyber-defence-network-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Defence Network Engineer - **Company:** Grant Thornton UK LLP - **Location:** London, UK - **Contract:** Permanent contract - **Skills:** Microsoft Access, Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, System Configuration, Information Leak Prevention, Firmware, Identity and Access Management, Intrusion Detection Systems, Subnetting, Virtual Private Networks (VPN), Network Security, Network Layer, Routing, Network Segmentation, PCI Data Security Standards, Proprietary Software, Role-Based Access Control, Remote Access Technology, Azure Active Directory, Zero Trust Network Access, Web Application Security, Security Information and Event Management, Virtual Local Area Networks, Wide Area Networks, Data Logging, Data Classification, Sonicwall, Firewalls (Computer Science), Palo Alto Networks, Fortinet, CIS Benchmarks, Firepower, Terraform, Oracle Cloud Infrastructure, Cisco - **Published:** September 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=96f00721a2352d7e ## About the Role Joining us as an experienced Network Engineer, the minimum criteria you'll need is a background in network engineering with demonstrable experience of applying it to security outcomes, ideally with 36 months in a security-focused role, together with the Netskope Certified Cloud Security Integrator (NCCSI), which you must be actively working towards if you do not already hold it. You should also be able to demonstrate the following during the interview process. Technical experience * Networking: LAN/WAN, VLAN segmentation, layer 2 / layer 3 access control, routing and switching, DMZ architecture, DNS and DHCP. A background as a network engineer prior to moving into security. * Network security: Cisco (including Firepower), Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel and F5. Firewall policy design and review, IPS/IDS, site-to-site and remote access VPN, and SSL/TLS inspection. * SASE and Zero Trust: Netskope One, Secure Web Gateway, CASB, Private Access (ZTNA) and DLP. Client deployment, steering configuration, tenant configuration and troubleshooting. * Cloud: Microsoft Azure (NSGs, Azure Firewall, Azure Policy, Defender for Cloud), Microsoft 365 and Entra ID (conditional access, PIM, Entra Connect), AWS and Oracle Cloud. Terraform for infrastructure as code. * Endpoint and detection: CrowdStrike Falcon (EDR, NG-SIEM, LogScale). * Identity: Active Directory, Entra ID, Group Policy, RBAC and privileged access. Frameworks: NIST CSF and NIST 800-53, CIS Benchmarks, and ISO 27001. * Qualifications and certifications You will hold, or be actively working towards, the Netskope Certified Cloud Security Integrator (NCCSI). This is a minimum criterion for the role. Beyond this, you will hold, or be working towards, a relevant combination of the following: * Cisco Certified Network Associate (CCNA) * Cisco Certified Entry Networking Technician (CCENT) * AWS Certified Cloud Practitioner * Microsoft Certified: Azure Fundamentals (AZ-900) * Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900) * Oracle Cloud Infrastructure Foundations Associate * Microsoft Certified Technology Specialist (MCTS) ITIL Foundation v3 * Soft skills * Communication: A clear and confident communicator with strong written and verbal skills, particularly in high-pressure scenarios. Able to translate technical detail for non-technical audiences, including clients, vendors and senior stakeholders. * Analytical thinking: Able to analyse complex environments and data, identify patterns and make evidence-based decisions. * Problem solving: Strong troubleshooting skills and the ability to develop solutions quickly and effectively during active incidents. * Teamwork and collaboration: Comfortable working closely with DFIR, SOC, Cyber Advisory and client technical teams. Collaboration is essential during incident response. * Adaptability: Able to embrace and manage change effectively, continuously developing skills to meet the demands of an evolving threat landscape. * Time management: Able to prioritise effectively while managing multiple engagements and ensuring SLAs, KPIs and client deadlines are met. Attention to detail: Careful and precise when making changes in live client environments, with high-quality, accurate documentation of every action taken. * ## Description As a Network Engineer within the Cyber Defence Centre, you will deliver the containment and recovery phases of live client incidents, and work on assessment, hardening and implementation engagements between them. Incident response, containment and recovery * Delivering the containment and recovery phases of live client security incidents, including ransomware, business email compromise and perimeter device exploitation. * Isolating affected systems and accounts, restricting compromised identities, closing off attacker access routes, and preventing further spread across the estate. * Preserving logs and evidence for the forensic investigation team, and working alongside them as the investigation develops. * Supporting client recovery, including rebuild and restoration sequencing driven by business priority, and ensuring known weaknesses are not reintroduced. * Implementing the remediation and hardening work identified through the incident, where clients engage us to deliver it. Working to the NIST Cyber Security Framework and incident response lifecycle, with CIS Benchmarks used for technical control recommendations. * Security assessment and hardening * Performing security reviews and configuration hardening across Microsoft 365 and Entra ID, Microsoft Azure, Amazon Web Services, on-premise Active Directory, and perimeter firewall estates. * Conducting firewall security assessments across multiple vendor platforms: rule base review, management plane exposure, VPN and remote access configuration, IPS/IDS posture, logging, and firmware currency. * Assessing cloud configuration against CIS Benchmarks and NIST using tooling including Prowler, ScubaGear and PingCastle, and turning technical findings into prioritised, business-contextualised remediation plans. * Reviewing third-party software, cloud applications and SaaS platforms as part of supplier and technology assurance work. Supporting client compliance and assurance requirements including GDPR, Cyber Essentials Plus and PCI DSS. * Security solution design and implementation * Designing and implementing security solutions in client environments, from discovery and requirements gathering through build, testing, rollout and handover. * Working as part of the delivery team on a Zero Trust access programme built on Netskope One SASE, covering Secure Web Gateway, CASB (inline and API), Private Access (ZTNA) and Data Loss Prevention, integrated with Microsoft Entra ID and endpoint management. * Designing and deploying Microsoft 365 conditional access policy sets, including MFA enforcement, legacy authentication blocking, device compliance conditions, geolocation restriction, and Privileged Identity Management for just-in-time privileged access. * Designing network segmentation across cloud and on-premise environments: Azure Network Security Groups and subnet-level control, VLAN segregation, DMZ isolation, and layer 2 / layer 3 access control. * Designing data classification and DLP policy, working with client data and business process owners to define label sets and handling outcomes, and validating policy behaviour in simulation before enforcement. Producing security architecture artefacts, hardening standards, deployment guides, operating procedures and SOC playbooks so client teams can operate and extend what you have built. * ## Related Videos - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [WeAreDevelopers LIVE - Back to CODE100](https://www.wearedevelopers.com/videos/1909-wearedevelopers-live-back-to-code100) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Salary London](https://www.wearedevelopers.com/magazine/252-software-engineer-salary-london) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)