> Markdown version of [/jobs/ext/347442-cyber-security-engineer](https://www.wearedevelopers.com/jobs/ext/347442-cyber-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Security Engineer - **Company:** Nova Blue Technologies - **Location:** UK (Remote available) - **Experience:** Experienced - **Salary:** £60,000.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Windows, Artificial Intelligence, Microsoft Azure, Configuration Management, Cyber Security, Windows PowerShell, Kusto Query Language, Security Information and Event Management, EndPointSecurity, Azure Automation, Mitre Att&ck, Microsoft InTune, Microsoft Sentinel, CIS Benchmarks, Software Version Control - **Published:** June 18, 2026 - **Apply:** https://uk.indeed.com/viewjob?jk=611abdfa733c6dd4 ## About the Role Do you have experience in PowerShell?, Must-have * Hands-on Microsoft Sentinel experience: writing KQL, building analytics rules, and deploying automation * PowerShell scripting for real automation, not just one-liners * Working knowledge of the Microsoft 365 security stack (Defender for Endpoint, Entra ID, Intune) * Source control as a professional discipline * A root-cause mindset: you chase the cause, not just the symptom * Innovation, curiosity, and agility: you look for better ways to do things, and you are in it for the ride * Strong customer-facing communication skills * Right to work in the UK Strong preference * MDR or SOC engineering background * Microsoft Azure automation experience * Experience deploying security baselines or configuration management at scale (CIS or similar) * Intermediate-to-advanced KQL (enrichment, correlation, custom workbooks) * Experience in an MSSP or multi-tenant environment Good to have * Familiarity with MITRE ATT&CK as a detection framework * Interest or experience in applying AI and MCP-based tooling to automation * Experience with threat intelligence and automated IOC tooling such as STIX and OpenCTI, including judging feed quality and value for money * Awareness of UK public sector or MOD supply chain security requirements * A multidisciplinary interest in startup functions such as product management and service delivery * A second spoken and written language, German especially, * Languages: English (required); German or another second language an asset, * DSC: 2 years (preferred) * KQL: 2 years (preferred) * SIEM: 2 years (preferred) * Azure Automation: 2 years (preferred) Language: * English (required) ## Description You will own the detection and automation behind two of our core services: MIDAS, our flagship Microsoft 365 managed security service, and ATLAS, our Sentinel-based SIEM and SOAR service. A strong foundation is already built. Your job is to take it further. The role rests on two equal pillars. Pillar 1: Customer Sentinel and detection. You will run regular Sentinel deployments: meeting customers, working out what they actually need, and iterating towards a solve. We manage our use case libraries in sprints, so you have the room to do the job properly. Detection is not about generating more alerts. It is about orchestrating them well, killing false positives and automating response so on-call analysts are only paged when a human is genuinely needed. Pillar 2: Internal automation at scale. You will own the PowerShell and Microsoft Azure automation that rolls out proactive security configurations and CIS baselines across customer tenants. Harden once, apply everywhere. The better this works, the lighter the alert load downstream and the more time the whole team gets back. There is plenty of room to push it further, including with AI and MCP-based tooling. These two pillars feed each other, and you will shape how they come together as we scale, extending the framework beyond Microsoft 365 and Azure when the time is right. You will report to the COO and work in concert with the managed services team lead. You will spend real time with customers and within their change management processes, because we care about doing things the right way and communicating clearly. Above all, this role keeps customers from getting breached. That is the point. This is a single contributor role within a matrix team: you own the technology, not a line-management chain. As we grow, the team may grow with it, and if you do a great job and show leadership potential, you could be the person who ends up leading it. We are a small company, so people wear many hats, and a multidisciplinary interest in how a startup runs, including product management and service delivery, will be a real asset. What You'll Do * Run regular customer Sentinel deployments: gather requirements, build use cases, and iterate towards a solve * Orchestrate alerts and automation so on-call analysts are paged only when it truly matters * Own and evolve the PowerShell and Azure automation that deploys security configurations and CIS baselines at scale * Work with service delivery owners to turn baseline improvements into automated, repeatable controls * Deliver scoped security configuration work across the Microsoft 365 stack (Defender, Entra, Intune, Purview) * Write clear SOPs so good work becomes repeatable * Act as the technical subject matter expert in customer conversations ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies)