At a Glance
- Tasks: Secure and enhance cloud environments using Microsoft Azure and Microsoft 365 technologies.
- Company: Join Cyro, a leader in Cyber Security with a focus on innovation and collaboration.
- Benefits: Enjoy competitive salary, flexible working, 25 days holiday, and professional development opportunities.
- Other info: Great career growth potential and a chance to work with major clients in critical infrastructure.
- Why this job: Make a real impact in cloud security while developing your skills in a supportive environment.
- Qualifications: Hands-on experience with Azure security and strong troubleshooting skills required.
The predicted salary is between 63000 - 77000 £ per year.
Working Pattern: Hybrid (at least 3 days in office)
Job Type: Permanent
Level: SFIA 4
Reports to: Principal Security Design Consultant
THE VACANCY: The Cloud Security Engineer role is designed for a hands-on security specialist with broad Microsoft Azure and Microsoft 365 experience who can implement, harden and assure cloud security controls. Candidates may have progressed through cloud engineering, infrastructure, identity and access management, security operations or consultancy roles and will be comfortable working directly in client environments. The role supports a varied portfolio of predominantly Azure security work spanning identity and privileged access, platform governance, networking, workload protection, secrets and encryption, logging and monitoring, data protection and automation. Strong practical experience with Microsoft Entra Privileged Identity Management and wider Privileged Access Management capabilities is particularly valued, alongside experience with Microsoft Purview across information protection, data classification and data loss prevention. This is not an exclusively identity or data-security role. The successful candidate will be expected to apply their core areas of expertise while developing and maintaining capability across the wider Azure and Microsoft 365 security landscape. Sitting within Cyro’s Cyber Security Architecture team, the successful candidate will work closely with security architects to translate security requirements and High-Level Designs into detailed, implementable solutions. They will own Low-Level Designs, build documentation and engineering delivery, while contributing to High-Level Designs, reference architectures and reusable security patterns. The role provides a clear development path towards security architecture for candidates with the aptitude and ambition to progress in that direction.
Primary responsibilities:
- Azure Security Engineering: Implement, configure, harden and troubleshoot security controls across Azure and Microsoft 365 environments.
- Configure Microsoft Entra ID controls including Conditional Access, multi-factor authentication, role-based access control, managed identities, access reviews and identity lifecycle controls, with particular emphasis on Privileged Identity Management and the application of appropriate privileged access controls.
- Implement platform governance using management groups, subscriptions, landing zone controls, Azure Policy and initiatives, Defender for Cloud, secure score and regulatory compliance capabilities.
- Engineer network security controls including virtual networks, network security groups, Azure Firewall, web application firewall, Private Link and private endpoints, DNS security, DDoS protection and hybrid connectivity controls.
- Implement Key Vault, encryption, secret and certificate management, secure storage patterns and workload identity controls.
- Secure Azure workloads including virtual machines, containers and AKS, App Service, Functions, storage, databases and other platform services.
- Configure security logging and monitoring using Azure Monitor, Log Analytics and Microsoft Sentinel, and integrate relevant Defender XDR telemetry.
- Implement Microsoft Purview capabilities where required, including information protection, sensitivity labels, data classification, data loss prevention, retention and records controls.
- Investigate and resolve cloud security issues, configuration drift, policy non-compliance and implementation defects, documenting root cause and corrective action.
Automation and DevSecOps:
- Build and maintain secure, repeatable deployments using Bicep, Terraform, PowerShell, Azure CLI or equivalent infrastructure-as-code and automation tooling.
- Integrate security guardrails, policy-as-code, secrets handling and security testing into Azure DevOps or GitHub-based delivery pipelines.
- Develop scripts, reusable modules and operational runbooks that improve consistency, supportability and delivery efficiency.
Design, Assurance and Documentation:
- Gather technical requirements, contribute to HLDs and own LLDs, build guides, configuration standards, test plans, runbooks and as-built documentation, progressively taking on greater design responsibility with support from experienced security architects.
- Perform cloud security configuration reviews and hardening assessments against Microsoft security guidance, CIS benchmarks, the NCSC CAF, ISO 27001 and client standards.
- Test changes, remediate findings and provide implementation assurance and operational handover to client and managed service teams.
Client and team engagement:
- Lead defined engineering work packages under general direction, planning activity, managing dependencies and maintaining delivery quality.
- Work directly with client architects, engineers, service teams and stakeholders to explain implementation choices, risks and operational impacts.
- Support technical discovery, estimates, proposals and client demonstrations, and contribute to reusable patterns and the development of Cyro's cloud security services.
Essential skills and experience:
- Strong hands-on experience engineering and securing Microsoft Azure environments.
- Practical capability across several Azure security domains, including identity, governance, networking, workload protection, logging and secrets management.
- Experience with Microsoft Entra ID, including practical exposure to Privileged Identity Management, together with experience across a selection of Azure security technologies such as Azure Policy, Defender for Cloud, Key Vault, Azure Monitor and Log Analytics.
- Experience using infrastructure-as-code or scripting tools such as Bicep, Terraform, PowerShell or Azure CLI.
- Ability to interpret architectural requirements and translate HLDs into accurate LLDs, build documentation, test plans and operational runbooks.
- Strong troubleshooting skills and experience resolving cloud configuration, access, policy and integration issues.
- Understanding of cloud security principles including least privilege, defence in depth, secure-by-design, segmentation, encryption and continuous monitoring.
- Good client-facing communication, documentation and stakeholder engagement skills.
- Ability to work autonomously under general direction, lead defined work packages and guide colleagues where appropriate.
- Eligibility for UK Security Clearance (successful appointment will be subject to being granted Security Clearance).
- Willingness to work across a varied portfolio of cloud security engineering activities, applying existing strengths while developing capability in other areas.
Desirable Skills and Experience:
- Hands-on experience with Microsoft Purview, particularly Information Protection, sensitivity labels, data classification or data loss prevention.
- Microsoft certifications such as AZ-500, AZ-104, SC-300, SC-400 or SC-100.
- Experience with Microsoft Sentinel, Defender XDR or Defender for Cloud Apps.
- Experience implementing security controls through Azure DevOps or GitHub CI/CD pipelines.
- Knowledge of the Microsoft Cloud Security Benchmark, CIS Azure benchmarks, the NCSC CAF, ISO 27001 or NIST guidance.
- Experience securing hybrid environments or familiarity with AWS or GCP security controls.
- Exposure to security design or architecture activities, or a demonstrable interest in developing towards a security architecture role.
- Experience working in or with Critical National Infrastructure, UK Government or similarly regulated environments.
Levels of responsibility: SFIA Level 4
So why choose Cyro for your next opportunity? To build, run and maintain a successful compliance programme, you need a connected approach – a team you can trust from strategy to support, and everything in between. At Cyro, this is what we do! As part of our team, you could be working with some of the biggest names in the Critical Nation Infrastructure and Service Provider sectors including London Underground, Network Rail, Transport for London, RNLI, MOD and more. You’ll help us ensure the most important messages get through – however tough the conditions.
Here are just some of the ways we’re different:
- You’ll go further with us. We understand the importance of career development and will give you all the support you need to realise your potential. You’ll receive formal training, e-learning and mentoring from top professionals. And we offer opportunities to transfer to other sectors – or even different technology areas.
- You’ll make a difference. You could be working outdoors, battling the elements, or in one of our many offices helping us develop the network infrastructures of tomorrow.
- You’ll be treated as an individual. We’re not a vast corporation, which means every individual counts. With us, you’ll be valued and supported, involved and empowered from day one.
- You’ll be well rewarded. We offer salary progression that reflects market rates and personal performance, a flexible working environment and excellent training. Cyro is committed to ensuring that we offer industry leading career opportunities, salary and benefits packages.
Join us and you can expect to receive: 25 days holiday, including public holidays, plus the option to buy or sell five days each year. Cyro is an equal opportunities employer and is committed to diversity and inclusion.
We reserve the right to close this vacancy once we have received sufficient applications. This job description sets out the duties and responsibilities of the job at the time when it was drawn up. Such duties and responsibilities may vary from time to time without changing the general character of the duties or the level of responsibility entailed. Such variations are a common occurrence and cannot in themselves justify a reconsideration of the grading of the job.
Cloud Security Engineer in London employer: Cyro Cyber Ltd
At Cyro, we pride ourselves on being an exceptional employer, offering a supportive and inclusive work culture that values each individual. As a Junior Cyber Security Engineer, you'll benefit from comprehensive training and career development opportunities while working with prestigious clients in the Critical National Infrastructure sector. Our flexible hybrid working model, competitive salary progression, and commitment to employee well-being make Cyro a rewarding place to build your career.
StudySmarter Expert Advice🤫
We think this is how you could land Cloud Security Engineer in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Cyro Cyber Ltd, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Cyro Cyber Ltd
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Cyro Cyber Ltd. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace Cloud Security Engineer in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Cyro Cyber Ltd insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Cyro Cyber Ltd that you’re committed to staying ahead in the game.
How to prepare for a job interview at Cyro Cyber Ltd
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Cyro Cyber Ltd to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Cyro Cyber Ltd.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.