- Monitor security alerts and events from security monitoring platforms and managed SOC providers
- Investigate and respond to security incidents, coordinating containment, eradication, and recovery activities
- Support vulnerability management, remediation tracking, and reporting
- Assist with threat intelligence gathering and analysis
- Maintain and improve the Information Security Management System (ISMS)
- Conduct security risk assessments and maintain risk registers
- Assist with ISO 27001, Cyber Essentials, and client assurance audits
- Review and update security policies, standards, and procedures
- Support secure adoption and governance of AI technologies
- Conduct security and privacy risk assessments for AI platforms and third-party AI providers
- Evaluate AI solutions against security, privacy, regulatory, and ethical requirements
- Develop and maintain AI governance policies and acceptable-use requirements
- Monitor AI-related threats, vulnerabilities, and regulatory developments
- Support controls preventing unauthorised AI use and confidential-information exposure
- Guide users on secure and responsible use of Generative AI, including Microsoft Copilot
- Perform third-party supplier security reviews and due diligence
- Review security questionnaires and assess supplier risks
- Monitor third-party security compliance
- Support security awareness programmes and phishing simulations
- Develop employee guidance and educational materials
- Support cyber incident investigations and post-incident reviews
- Maintain incident response documentation and playbooks
- Participate in incident response exercises and tabletop testing
- Assist with business continuity and disaster recovery planning
- Support deployment and management of Microsoft Purview, Microsoft Defender, Microsoft Sentinel, Microsoft Entra ID, email security solutions, endpoint protection technologies, and vulnerability management platforms
- Assist with security configuration reviews and hardening
- Produce security metrics, dashboards, and management reports
- Communicate technical security issues to technical and non-technical audiences
- Recommend improvements to security controls and risk reduction
Requirements
- Strong experience in a cyber security, information security, or security operations role
- Good understanding of ISO 27001
- Good understanding of NIST Cyber Security Framework
- Good understanding of Cyber Essentials Plus
- Good understanding of risk management methodologies
- Experience investigating security incidents
- Knowledge of Microsoft 365 security technologies
- Understanding of networking, operating systems, cloud technologies, and identity management
- Strong analytical and problem-solving skills
- Excellent written and verbal communication skills
- Experience with Microsoft Sentinel and Defender XDR is desirable
- Experience with third-party risk management is desirable
- Knowledge of GDPR and data protection requirements is desirable
- Experience working with managed SOC providers is desirable
- Exposure to security awareness and phishing simulation programmes is desirable
- Essential degree in Cyber Security, Information Technology, Computer Science, or equivalent experience
- CISSP, SSCP, CompTIA Security+, or Microsoft Security Certifications (SC-200, SC-300, SC-100) are desirable
- Self-motivated and proactive
- Strong attention to detail
- Able to prioritise and manage multiple activities simultaneously
- Collaborative team player with a customer-focused approach
- Strong commercial awareness and ability to balance security with business objectives
- Passionate about staying current with emerging threats and technologies
Core Competencies
Demonstrates expertise in Cyber Security and Information Security Management, with a strong focus on risk management, incident response, and compliance with ISO 27001 and NIST Cyber Security Framework. Proficient in utilizing Microsoft security technologies and managing third-party security risks while fostering a culture of security awareness.
Highest-signal resume keywords
- Cyber Security Experience
- ISO 27001 Understanding
- Microsoft Sentinel Proficiency
- Risk Management Methodologies
- Incident Response Coordination
ATS Optimization Keywords
Hard Skills
- Security Incident Investigation
- Vulnerability Management
- Threat Intelligence Analysis
- Security Risk Assessment
- Security Policy Development
- AI Governance Policies
- Security Metrics Production
- Third-Party Risk Management
- GDPR Knowledge
- Networking and Cloud Technologies
Soft Skills
- Analytical Problem-Solving
- Excellent Communication
- Attention to Detail
- Self-Motivated
- Collaborative Team Player
Certifications & Qualifications
- CISSP
- SSCP
- CompTIA Security+
- Microsoft Security Certifications (SC-200, SC-300, SC-100)
Industry Keywords
- NIST Cyber Security Framework
- Cyber Essentials Plus
- Information Security Management System (ISMS)
- Security Awareness Programs
- Phishing Simulations
Tools & Technologies
- Microsoft Purview
- Microsoft Defender
- Microsoft Sentinel
- Email Security Solutions
- Endpoint Protection Technologies
- Vulnerability Management Platforms
#J-18808-Ljbffr
Cyber Security Engineer employer: Jobtailor
As a Client Services Coordinator at our dynamic company, you will thrive in a supportive work culture that prioritises employee growth and development. We offer comprehensive training, opportunities for advancement, and a collaborative environment where your contributions are valued. Located in a vibrant area, our team enjoys a healthy work-life balance and the chance to engage with diverse clients, making every day rewarding and meaningful.