We are currently looking for a Microsoft Security Engineer to join an existing team with one of our key clients in financial services. The role will operate as a hybrid technical lead and delivery engineer, with a primary focus on M365 implementation, but will also provide flexible support across adjacent workstreams including incident response support, detection engineering, and log enrichment.
Responsibilities
- Own and manage the configuration of the Microsoft Security Stack, including Defender for Endpoint, Identity, Cloud, and Office 365.
- Configure and maintain Microsoft Defender features, policies and results and ensure alerts are monitored and actioned appropriately.
- Support operational excellence through timely alert management, policy tuning and threat analysis.
- Rapidly adapt to and implement new Microsoft features and tools as they are procured.
- Recommend and present security improvements to senior stakeholders.
- M365 Security Configuration and baseline
- Configure and maintain the full Microsoft Security Stack (Defender for Endpoint, Identity, Cloud, Office).
- Maintain and review the Entra ID (Azure AD) and Intune estate to ensure optimal performance and compliance.
- Ensure integration and operationalisation of Defender detection and telemetry into central SIEM solution.
- Collaborate with Cyber Security, Infrastructure, and IT teams.
Skills & Experience
- Proven experience configuring and managing the Microsoft Security Stack in an enterprise environment.
- Strong working knowledge of Microsoft Defender, Sentinel, Entra ID (Azure AD), and Intune.
- Experience with security alert management, policy configuration, and threat analytics.
- Ability to work independently and take ownership of technical domains.
- Strong communication skills with the ability to engage and influence senior stakeholders.
- Experience working in cross-functional teams across multiple regions.
Desirable Qualifications
- Microsoft certifications such as SC-200: Microsoft Security Operations Analyst
- SC-300: Identity and Access Administrator
- AZ-500: Azure Security Engineer Associate
- MS-102: Microsoft 365 Administrator
- Experience contributing to SIEM migration or replacement projects
Contract will be remote working with occasional office visits, contract will be outside IR35.
#LI-DNI