Skip to content

Open nowPosted 316 days ago

Security Engineer – Cloud & On-Prem (Hybrid Security)

spacenk167 open roles

Where
London, United Kingdom
Work mode
Hybrid
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity Engineer – Cloud & On-Prem (Hybrid Security)spacenk · London, United Kingdom
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on spacenk's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 316 days ago

The posting

If you love beauty, you’re in the right place.

As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go-to destination for worldwide beauty discovery.

Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands.

Job Role: Security Engineer – Cloud & On-Premises (Hybrid Security)

  • Location: London Head Office/Hybrid
  • Duration: Permanent
  • Department: Technology
  • Reporting to: Platform Engineering Principal

About the Role

Space NK operates a hybrid technology environment spanning Microsoft Azure, Microsoft 365, corporate infrastructure, distribution environments and a nationwide retail estate. The Security Engineer helps protect, monitor and continually improve security across our cloud and on-premises estate.

This is a hands-on engineering role for someone with a sound foundation in cyber security and Microsoft technologies who wants to build deeper capability across Azure security, Microsoft Defender, Sentinel, identity security, vulnerability management and incident response.

Working within Platform Engineering, you will collaborate with Cyber Security, Infrastructure, Cloud, Network, Application, Service and Operations teams to investigate security events, implement agreed controls, remediate vulnerabilities and support security improvement and transformation initiatives.

The role offers clear scope to develop expertise in cloud security, threat detection, security automation and incident response, with increasing technical ownership as your experience grows.

Key Responsibilities

Cloud & Infrastructure Security

• Administer and support security controls across Microsoft Azure, Microsoft 365 and on-premises infrastructure.

• Support the implementation and maintenance of Microsoft Defender for Cloud, including security recommendations, posture management and workload protection.

• Assist with security controls across Azure services including Key Vault, Azure Firewall, Private Link, Network Security Groups and Azure Policy.

• Review cloud security configurations and identify misconfigurations, excessive permissions and potential security weaknesses.

• Support the implementation of security baselines, hardening standards and Zero Trust principles across cloud and on-premises environments.

• Work with Infrastructure, Network and Cloud teams to remediate identified security risks.

• Support security reviews for new and existing infrastructure services.

Security Monitoring & Threat Detection

• Monitor and investigate security alerts using Microsoft Sentinel, Microsoft Defender XDR and associated security platforms.

• Analyse security events across identity, endpoint, server, network and cloud environments.

• Investigate suspicious activity and determine the scope, impact and appropriate next actions.

• Review logs and telemetry from Entra ID, Azure, Microsoft 365, endpoints, firewalls and other infrastructure platforms.

• Support the development and tuning of Sentinel analytics rules, alerts, dashboards and detection logic.

• Perform proactive security analysis and threat-hunting activities using available security telemetry.

• Work directly with our SOC/MSSP and security partners to investigate alerts and coordinate technical actions.

Incident Response

• Investigate security incidents and support containment, remediation and recovery activities.

• Gather and analyse relevant logs, endpoint information, identity activity and other technical evidence.

• Carry out approved containment actions such as isolating endpoints, disabling accounts, revoking sessions or blocking malicious indicators.

• Work with Cyber Security, Infrastructure, Network and Application teams during incident investigation and remediation.

• Escalate high-risk or complex incidents appropriately while maintaining ownership of assigned investigative activities.

• Document incidents, technical findings, actions and lessons learned.

• Contribute to post-incident reviews and implementation of corrective actions.

Endpoint, Identity & Infrastructure Security

• Support security controls across Windows endpoints, servers and cloud workloads using Microsoft Defender technologies.

• Investigate endpoint alerts, suspicious processes, malware and other potentially malicious activity.

• Work with the Identity team on security issues involving Entra ID, Conditional Access, MFA, privileged accounts and risky users.

• Support the review and remediation of inappropriate or excessive permissions.

• Assist with server and endpoint hardening in accordance with agreed security baselines.

• Support the identification and reduction of legacy or insecure protocols, configurations and services.

• Work with the Network team on security events involving firewalls, VPNs, segmentation and suspicious network traffic.

Vulnerability & Security Posture Management

• Review vulnerability and security posture information across cloud, endpoint, server and infrastructure environments.

• Assess vulnerabilities based on severity, exposure and potential business impact.

• Work with technical teams to coordinate and track remediation activities.

• Validate remediation and help identify recurring security weaknesses.

• Support vulnerability scanning and remediation programmes.

• Monitor Microsoft Secure Score, Defender for Cloud recommendations and other security posture indicators.

• Contribute to continuous improvement of Space NK's security posture.

Governance, Compliance & Security Improvement

• Apply Zero Trust, least privilege and secure-by-default principles to day-to-day security engineering.

• Implement and maintain agreed security controls and technical standards.

• Support security requirements relating to PCI DSS, SOX, GDPR, ISO 27001 and other applicable frameworks.

• Assist with audit evidence gathering, control validation and remediation activities.

• Maintain security documentation, procedures and technical records.

• Participate in change management and security reviews for infrastructure and cloud changes.

• Contribute to security improvement projects and initiatives across the organisation.

Automation & Continuous Improvement

• Identify opportunities to automate repetitive security activities and operational processes.

• Use PowerShell and other scripting technologies to support security administration and investigation.

• Develop skills across Microsoft Graph API, KQL, Azure CLI, Logic Apps and security automation.

• Support the development of Sentinel automation rules and playbooks.

• Contribute to improving security monitoring, detection and response processes.

• Maintain scripts and automation in a documented, controlled and repeatable manner.

Essential Experience

We're looking for someone with a strong technical security foundation and the potential to develop further, rather than an established Security Architect or subject matter expert.

You should have experience in several of the following areas:

• Hands-on experience in a Cyber Security, Security Operations, Infrastructure Security or related technical role.

• Practical experience with Microsoft security technologies or equivalent enterprise security platforms.

• Understanding of Microsoft Azure, Microsoft 365 and Entra ID security concepts.

• Experience investigating security alerts and suspicious activity.

• Understanding of endpoint security, malware protection and EDR/XDR technologies.

• Familiarity with SIEM technologies, log analysis and security monitoring.

• Understanding of vulnerability management and remediation processes.

• Good knowledge of fundamental security concepts including least privilege, MFA, network segmentation, encryption and Zero Trust.

• Understanding of common security threats and attack techniques such as phishing, credential compromise, malware and privilege escalation.

• Good troubleshooting and analytical skills.

• Ability to independently investigate routine security incidents and recognise when escalation is required.

• Good technical documentation and communication skills.

We don't expect candidates to be experts across every security technology. We're looking for strong technical foundations and someone keen to develop deeper expertise across Microsoft cloud and hybrid security.

Desirable Experience

Experience in any of the following would be advantageous:

• Microsoft Sentinel and Kusto Query Language (KQL).

• Microsoft Defender XDR, Defender for Endpoint or Defender for Identity.

• Microsoft Defender for Cloud and Cloud Security Posture Management.

• Entra ID security, including Conditional Access, Identity Protection and PIM.

• Azure security technologies including Key Vault, Azure Firewall and Azure Policy.

• Vulnerability management and security posture assessment.

• Incident response and threat hunting.

• Security automation using PowerShell, Microsoft Graph, Logic Apps or APIs.

• Network security and firewall technologies.

• Exposure to AWS security services such as GuardDuty, Security Hub, IAM or CloudTrail.

• Experience working with an external SOC, MSSP or security service provider.

• Exposure to PCI DSS, SOX, GDPR, ISO 27001, CIS or NIST environments.

Qualifications & Certifications

A degree in Cyber Security, Computer Science, Information Technology or a related discipline is advantageous but not essential where equivalent practical experience can be demonstrated.

We would typically expect approximately 2–5 years of relevant security, infrastructure or cloud engineering experience, although technical capability, attitude and potential are more important than a specific number of years.

Relevant certifications are desirable but not mandatory, including:

• Microsoft Security Operations Analyst Associate (SC-200)

• Microsoft Azure Security Engineer Associate (AZ-500)

• Microsoft Security, Compliance and Identity Fundamentals (SC-900)

• Microsoft Azure Fundamentals (AZ-900)

• CompTIA Security+

• CompTIA CySA+ or equivalent

Candidates actively working towards relevant security or Microsoft certifications are also encouraged to apply.

Skills & Attributes

• Strong interest in cyber security, cloud technologies and threat detection.

• Logical and methodical approach to security investigation and troubleshooting.

• Able to take responsibility for assigned incidents and technical work while recognising when escalation is required.

• Comfortable analysing technical evidence and working through an investigation to resolution.

• Good written and verbal communication skills.

• Collaborative approach when working with Cyber Security, Infrastructure, Cloud, Network, Applications and Service teams.

• Comfortable working directly with SOC/MSSP and technology partners when required.

• Willingness to learn new technologies and continually develop security knowledge.

• Good understanding of change control, documentation and production environments.

• Proactive approach to automation, security improvement and continuous learning.

Development & Progression

This role provides the opportunity to develop deeper capability across Microsoft Sentinel, Defender XDR, Defender for Cloud, Azure security, threat hunting, incident response, vulnerability management and security automation.

As technical capability and experience grow, the engineer will take increasing responsibility for complex security investigations, technical solutions and project delivery, providing a natural development path towards a Senior Security Engineer – Cloud & On-Premises (Hybrid Security) role.

Please note that only successful candidates will be contacted.

All applicants must have the right to live and work in the UK.

If you want to find out more about us, what it is like to work for us, all about our benefits, and our pledges on Diversity, Inclusion and Belonging, please visit our website.

Space NK are an equal opportunities employer.

How We Will Use Your Information

We will use the information you provide to us with your job application to help us process your application for the specific job you have applied for. If you apply speculatively, we will process your application for the job/relevant business area that you detail within your email.

Please note that our current system does not use an automated filtering system.

All applications made via the website, through a third-party website or in-store will be kept on file for a period of 12 months.

This information will be retained and used to assess your suitability to similar positions that may arise in the future, or if the initial vacancy becomes live again during the 12-month period. If you would prefer us to not hold your information on file/ you wish to be ‘forgotten’ if you are not offered a position with Space NK, please email your ‘right to be forgotten’ to our recruitment email address with RIGHT TO BE FORGOTTEN as the title of the email. We will always inform you when we have deleted your application details, otherwise we will treat your application as consent to us holding this information.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against spacenk's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on spacenk's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    spacenk's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.