Security Engineer – Cloud & On-Prem (Hybrid Security)

Space NKLondon, EnglandOn-siteFull-timeJunior, 1–2 yearsListed 1 hour ago

Apply now

About this role

If you love beauty, you’re in the right place.

As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go-to destination for worldwide beauty discovery.

Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands.

Job Role: Security Engineer – Cloud & On-Premises (Hybrid Security)

- Location: London Head Office/Hybrid
- Duration: Permanent
- Department: Technology
- Reporting to: Platform Engineering Principal

About the Role

Space NK operates a hybrid technology environment spanning Microsoft Azure, Microsoft 365, corporate infrastructure, distribution environments and a nationwide retail estate. The Security Engineer helps protect, monitor and continually improve security across our cloud and on-premises estate.

This is a hands-on engineering role for someone with a sound foundation in cyber security and Microsoft technologies who wants to build deeper capability across Azure security, Microsoft Defender, Sentinel, identity security, vulnerability management and incident response.

Working within Platform Engineering, you will collaborate with Cyber Security, Infrastructure, Cloud, Network, Application, Service and Operations teams to investigate security events, implement agreed controls, remediate vulnerabilities and support security improvement and transformation initiatives.

The role offers clear scope to develop expertise in cloud security, threat detection, security automation and incident response, with increasing technical ownership as your experience grows.

Key Responsibilities

Cloud & Infrastructure Security

• Administer and support security controls across Microsoft Azure, Microsoft 365 and on-premises infrastructure.

• Support the implementation and maintenance of Microsoft Defender for Cloud, including security recommendations, posture management and workload protection.

• Assist with security controls across Azure services including Key Vault, Azure Firewall, Private Link, Network Security Groups and Azure Policy.

• Review cloud security configurations and identify misconfigurations, excessive permissions and potential security weaknesses.

• Support the implementation of security baselines, hardening standards and Zero Trust principles across cloud and on-premises environments.

• Work with Infrastructure, Network and Cloud teams to remediate identified security risks.

• Support security reviews for new and existing infrastructure services.

Security Monitoring & Threat Detection

• Monitor and investigate security alerts using Microsoft Sentinel, Microsoft Defender XDR and associated security platforms.

• Analyse security events across identity, endpoint, server, network and cloud environments.

• Investigate suspicious activity and determine the scope, impact and appropriate next actions.

• Review logs and telemetry from Entra ID, Azure, Microsoft 365, endpoints, firewalls and other infrastructure platforms.

• Support the development and tuning of Sentinel analytics rules, alerts, dashboards and detection logic.

• Perform proactive security analysis and threat-hunting activities using available security telemetry.

• Work directly with our SOC/MSSP and security partners to investigate alerts and coordinate technical actions.

Incident Response

• Investigate security incidents and support containment, remediation and recovery activities.

• Gather and analyse relevant logs, endpoint information, identity activity and other technical evidence.

• Carry out approved containment actions such as isolating endpoints, disabling accounts, revoking sessions or blocking malicious indicators.

• Work with Cyber Security, Infrastructure, Network and Application teams during incident investigation and remediation.

• Escalate high-risk or complex incidents appropriately while maintaining ownership of assigned investigative activities.

• Document incidents, technical findings, actions and lessons learned.

• Contribute to post-incident reviews and implementation of corrective actions.

Endpoint, Identity & Infrastructure Security

• Support security controls across Windows endpoints, servers and cloud workloads using Microsoft Defender technologies.

• Investigate endpoint alerts, suspicious processes, malware and other potentially malicious activity.

• Work with the Identity team on security issues involving Entra ID, Conditional Access, MFA, privileged accounts and risky users.

• Support the review and remediation of inappropriate or excessive permissions.

• Assist with server and endpoint hardening in accordance with agreed security baselines.

• Support the identification and reduction of legacy or insecure protocols, configurations and services.

• Work with the Network team on security events involving firewalls, VPNs, segmentation and suspicious network traffic.

Vulnerability & Security Posture Management

• Review vulnerability and security posture information across cloud, endpoint, server and infrastructure environments.

• Assess vulnerabilities based on severity, exposure and potential business impact.

• Work with technical teams to coordinate and track remediation activities.

• Validate remediation and help identify recurring security weaknesses.

• Support vulnerability scanning and remediation programmes.

• Monitor Microsoft Secure Score, Defender for Cloud recommendations and other security posture indicators.

• Contribute to continuous improvement of Space NK's security posture.

Governance, Compliance & Security Improvement

• Apply Zero Trust, least privilege and secure-by-default principles to day-to-day security engineering.

• Implement and maintain agreed security controls and technical standards.

• Support security requirements relating to PCI DSS, SOX, GDPR, ISO 27001 and other applicable frameworks.

• Assist with audit evidence gathering, control validation and remediation activities.

• Maintain security documentation, procedures and technical records.

• Participate in change management and security reviews for infrastructure and cloud changes.

• Contribute to security improvement projects and initiatives across the organisation.

Automation & Continuous Improvement

• Identify opportunities to automate repetitive security activities and operational processes.

• Use PowerShell and other scripting technologies to support security administration and investigation.

• Develop skills across Microsoft Graph API, KQL, Azure CLI, Logic Apps and security automation.

• Support the development of Sentinel automation rules and playbooks.

• Contribute to improving security monitoring, detection and response processes.

• Maintain scripts and automation in a documented, controlled and repeatable manner.

Essential Experience

We're looking for someone with a strong technical security foundation and the potential to develop further, rather than an established Security Architect or subject matter expert.

You should have experience in several of the following areas:

• Hands-on experience in a Cyber Security, Security Operations, Infrastructure Security or related technical role.

• Practical experience with Microsoft security technologies or equivalent enterprise security platforms.

• Understanding of Microsoft Azure, Microsoft 365 and Entra ID security concepts.

• Experience investigating security alerts and suspicious activity.

• Understanding of endpoint security, malware protection and EDR/XDR technologies.

• Familiarity with SIEM technologies, log analysis and security monitoring.

• Understanding of vulnerability management and remediation processes.

• Good knowledge of fundamental security concepts including least privilege, MFA, network segmentation, encryption and Zero Trust.

• Understanding of common security threats and attack techniques such as phishing, credential compromise, malware and privilege escalation.

• Good troubleshooting and analytical skills.

• Ability to independently investigate routine security incidents and recognise when escalation is required.

• Good technical documentation and communication skills.

We don't expect candidates to be experts across every security technology. We're looking for strong technical foundations and someone keen to develop deeper expertise across Microsoft cloud and hybrid security.

Desirable Experience

Experience in any of the following would be advantageous:

• Microsoft Sentinel and Kusto Query Language (KQL).

• Microsoft Defender XDR, Defender for Endpoint or Defender for Identity.

• Microsoft Defender for Cloud and Cloud Security Posture Management.

• Entra ID security, including Conditional Access, Identity Protection and PIM.

• Azure security technologies including Key Vault, Azure Firewall and Azure Policy.

• Vulnerability management and security posture assessment.

• Incident response and threat hunting.

• Security automation using PowerShell, Microsoft Graph, Logic Apps or APIs.

• Network security and firewall technologies.

• Exposure to AWS security services such as GuardDuty, Security Hub, IAM or CloudTrail.

• Experience working with an external SOC, MSSP or security service provider.

• Exposure to PCI DSS, SOX, GDPR, ISO 27001, CIS or NIST environments.

Qualifications & Certifications

A degree in Cyber Security, Computer Science, Information Technology or a related discipline is advantageous but not essential where equivalent practical experience can be demonstrated.

We would typically expect approximately 2–5 years of relevant security, infrastructure or cloud engineering experience, although technical capability, attitude and potential are more important than a specific number of years.

Relevant certifications are desirable but not mandatory, including:

• Microsoft Security Operations Analyst Associate (SC-200)

• Microsoft Azure Security Engineer Associate (AZ-500)

• Microsoft Security, Compliance and Identity Fundamentals (SC-900)

• Microsoft Azure Fundamentals (AZ-900)

• CompTIA Security+

• CompTIA CySA+ or equivalent

Candidates actively working towards relevant security or Microsoft certifications are also encouraged to apply.

Skills & Attributes

• Strong interest in cyber security, cloud technologies and threat detection.

• Logical and methodical approach to security investigation and troubleshooting.

• Able to take responsibility for assigned incidents and technical work while recognising when escalation is required.

• Comfortable analysing technical evidence and working through an investigation to resolution.

• Good written and verbal communication skills.

• Collaborative approach when working with Cyber Security, Infrastructure, Cloud, Network, Applications and Service teams.

• Comfortable working directly with SOC/MSSP and technology partners when required.

• Willingness to learn new technologies and continually develop security knowledge.

• Good understanding of change control, documentation and production environments.

• Proactive approach to automation, security improvement and continuous learning.

Development & Progression

This role provides the opportunity to develop deeper capability across Microsoft Sentinel, Defender XDR, Defender for Cloud, Azure security, threat hunting, incident response, vulnerability management and security automation.

As technical capability and experience grow, the engineer will take increasing responsibility for complex security investigations, technical solutions and project delivery, providing a natural development path towards a Senior Security Engineer – Cloud & On-Premises (Hybrid Security) role.

Please note that only successful candidates will be contacted.

All applicants must have the right to live and work in the UK.

If you want to find out more about us, what it is like to work for us, all about our benefits, and our pledges on Diversity, Inclusion and Belonging, please visit our website.

Space NK are an equal opportunities employer.

How We Will Use Your Information

We will use the information you provide to us with your job application to help us process your application for the specific job you have applied for. If you apply speculatively, we will process your application for the job/relevant business area that you detail within your email.

Please note that our current system does not use an automated filtering system.

All applications made via the website, through a third-party website or in-store will be kept on file for a period of 12 months.

This information will be retained and used to assess your suitability to similar positions that may arise in the future, or if the initial vacancy becomes live again during the 12-month period. If you would prefer us to not hold your information on file/ you wish to be ‘forgotten’ if you are not offered a position with Space NK, please email your ‘right to be forgotten’ to our recruitment email address with RIGHT TO BE FORGOTTEN as the title of the email. We will always inform you when we have deleted your application details, otherwise we will treat your application as consent to us holding this information.