At a Glance
- Tasks: Evaluate threats to infrastructure and ensure secure delivery of cloud projects.
- Company: Dynamic legal firm with a focus on cyber security and innovation.
- Benefits: Flexible working, competitive salary, and opportunities for professional growth.
- Why this job: Join a team that protects vital systems and makes a real impact in cyber security.
- Qualifications: Experience in M365, Azure, and strong problem-solving skills required.
- Other info: Collaborative environment with excellent career advancement opportunities.
The predicted salary is between 36000 - 60000 £ per year.
Location for this role is flexible; however, presence will be required in our offices on occasion. Based in our Aberdeen, Edinburgh or Glasgow office.
Job Purpose
The role is responsible for evaluating threats and risks to the firm's infrastructure, in particular Azure and Microsoft 365. As the firm grows and more infrastructure moves to the Cloud, this new role will play a significant part in ensuring that projects, platforms and services are securely delivered.
As part of the infrastructure team, working alongside the firm’s Cyber Security Analyst, the Infrastructure Cyber Engineer will ensure the security of key platforms is continuously improved, including ensuring the Azure tenant remains protected and configured in line with security best practice. The successful candidate will need to be current with M365 and Azure security features, configuration settings and changes. The role holder will support the infrastructure team with incident response and assist with infrastructure maintenance and configuration, whether on premise or Cloud, aligning with security audit and testing requirements. They will also be responsible for investigating and responding to security alerts provided by systems such as Arctic Wolf, Darktrace, BitSight, Silverfort, Varonis and DMARC as escalated by the firm’s Cyber Security Analyst.
The role will be split between M365 and Azure security and system hardening both on-premises and in Azure but flexibility is required and the role is expected to assist with other infrastructure tasks depending on the team's workload. The successful candidate can be based in Aberdeen, Edinburgh or Glasgow, with flexibility on travel as there will be a requirement to work from any of our offices on occasion.
Core Tasks
- Review and remediation of M365 security and Azure landing space.
- Monitor and investigate alerts from security solutions and mitigate/treat risks including configuration recommendations arising from penetration and vulnerability testing of systems.
- Monitor the security of the network using a variety of network and cyber security tools and work with vendors to troubleshoot cyber security incidents.
- Work with the infrastructure team in the secure administration of network hardware and equipment, including routers, switches, hubs, and other systems as required.
- Work with Business Assurance colleagues to ensure Brodies continuously improves its Cyber and Information Security posture and complies with internal and external audits and standards.
- Assist with Disaster Recovery and Incident Response processes.
- Assist with the maintenance of policies and procedures documentation.
- Support the maintenance of Brodies' Information Security defences and certifications.
- Work with internal and external auditors as required and on preparation for audit visits.
- Investigate security alerts from the various information security systems, assess risk, triage and resolve problems, and complete incident reports.
- Work with the Infrastructure Manager on project work as required and coordinate some infrastructure projects from kick-off to completion.
- Be aware of Brodies’ information security policies, and protect information assets from unauthorised access, disclosure, modification, destruction or interference at all times.
- Be technical lead in infrastructure to cloud migration projects such as Azure site recovery.
Person Specification
To be successful in this role, you will be comfortable collaborating with technical and non-technical colleagues alike and managing the demands of key stakeholders. You will have excellent communication skills, both written and verbal, and will use them to build relationships with others. You will relish the opportunity to effect change and will be a keen problem solver with the ability to consider various viewpoints and business needs. You will be able to work as part of a team and individually, proactively identifying what is required and managing your workload. You will have a good understanding of offensive and defensive techniques, and an awareness of frameworks such as OWASP, Cyber Essentials Plus and ISO27001. Previous experience in Infrastructure, Network or Security, M365 and Azure or similar roles is preferred. Certification in Azure such as MS Azure Fundamentals, MS Azure security engineer associate, MS azure solutions architect. Legal or professional services experience is desirable but not essential.
Qualifications
The following qualifications are desirable:
- Certifications
- Cloud Compliance & Governance
- Knowledge on frameworks like GDPR, HIPAA, PCI-DSS, and secure migration best practices.
Skills
- Expertise in designing scalable, reliable, secure infrastructure (physical, virtual, cloud).
- Network Design & Management
- Strong knowledge of TCP/IP, DNS, DHCP, firewalls, IDS/IPS, VLANs, routing protocols, and network topologies.
- Proficiency with AWS, Azure, or GCP architecture, security controls, IAM, encryption, compliance (e.g., FedRAMP).
- Experience with VMware, Hyper-V or KVM, and container technologies like Docker/Kubernetes.
- Administration of Windows/Linux servers, patch management, backup/recovery, secure configurations.
- Cybersecurity Controls & Incident Response
- Familiar with incident response, threat detection, vulnerability assessments, SIEM, penetration testing, risk management.
- DevSecOps & Automation
- Skilled in Infrastructure-as-Code (Terraform, Ansible), CI/CD pipelines, and integrating security into DevOps cycles.
- Scripting & Tooling
- Proficiency in scripting languages such as Python, PowerShell, Bash for automation and forensic tasks.
Additional Skills
- Able to research problems and translate requirements into solutions.
- Proven problem solving and troubleshooting abilities.
- Able to effectively prioritise and execute tasks in a fast-paced environment.
- Confident communicator at all levels.
- Able to prioritise, manage competing priorities and manage change with ease.
Infrastructure Cyber Engineer employer: Brodies LLP
Contact Detail:
Brodies LLP Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Infrastructure Cyber Engineer
✨Tip Number 1
Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in cyber security. You never know who might have a lead on your dream job!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to Azure and M365 security. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews like a pro! Research common interview questions for Infrastructure Cyber Engineer roles and practice your responses. Be ready to discuss your experience with tools like Arctic Wolf and Darktrace, as well as your approach to incident response.
✨Tip Number 4
Don’t forget to apply through our website! We love seeing candidates who are genuinely interested in joining our team. Tailor your application to highlight your relevant skills and experiences, and let us know why you’re excited about the role!
We think you need these skills to ace Infrastructure Cyber Engineer
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Infrastructure Cyber Engineer role. Highlight your experience with Azure, M365, and any relevant security certifications. We want to see how your skills match what we're looking for!
Craft a Compelling Cover Letter: Your cover letter is your chance to shine! Use it to explain why you're passionate about cyber security and how you can contribute to our team. Keep it concise but impactful – we love a good story!
Show Off Your Communication Skills: Since this role involves collaborating with both technical and non-technical folks, make sure to showcase your communication skills in your application. We want to know how you can bridge the gap between different teams!
Apply Through Our Website: Don't forget to apply through our website! It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy – just a few clicks and you’re done!
How to prepare for a job interview at Brodies LLP
✨Know Your Stuff
Make sure you brush up on your knowledge of Azure and Microsoft 365 security features. Be ready to discuss specific tools like Arctic Wolf and Darktrace, as well as your experience with incident response and vulnerability assessments. Showing that you're current with the latest security practices will impress the interviewers.
✨Showcase Your Problem-Solving Skills
Prepare examples of how you've tackled security challenges in the past. Whether it’s a tricky incident response or a configuration issue, having concrete examples will demonstrate your ability to think critically and act decisively under pressure.
✨Communicate Clearly
Since this role involves collaborating with both technical and non-technical colleagues, practice explaining complex concepts in simple terms. Good communication skills are key, so be ready to showcase your ability to build relationships and convey information effectively.
✨Be Ready for Scenario Questions
Expect to face scenario-based questions that test your knowledge of security frameworks like OWASP and Cyber Essentials Plus. Think through potential security incidents and how you would respond, as this will show your practical understanding of the role and its responsibilities.