Security Engineer

Security Engineer

Full-Time 55000 - 65000 € / year (est.) No home office possible
Kennedys Law LLP

At a Glance

  • Tasks: Join our SecOps team to implement and maintain top-notch security measures.
  • Company: Kennedys, a leading firm with a focus on innovative security solutions.
  • Benefits: Flexible working, competitive salary, and opportunities for professional growth.
  • Other info: Collaborative environment with global reach and excellent career advancement potential.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience in EDR, SIEM, and a passion for cybersecurity.

The predicted salary is between 55000 - 65000 € per year.

Kennedys is looking for a Security Engineer to join Kennedys, who will be a vital member of our newly established SecOps team, reporting directly to the IT Security Manager. This position is crucial in implementing and maintaining robust security measures across our technology landscape, as well as managing incident response. The role involves developing, implementing, and sustaining security solutions designed to protect our systems against constantly evolving cyber threats, with a focus on transitioning to a zero-trust operating model. The Security Engineer will work collaboratively across IT functions, spearhead key security initiatives, and play a pivotal role in enhancing our overall security posture. The role will also support the firm in its pursuit of ISO 27001 certification and the implementation of CIS controls.

Team Kennedys' IT team is responsible for the maintenance of IT systems and security across the firm, including its portfolio of managed bespoke and off-the-shelf applications. This role will work across all IT functions and, in the case of broader projects, occasionally with other business functions within the firm. The majority of the global IT team are based in London and Chelmsford, although some staff are based in other UK and non-UK offices. As a team that provides a truly global service, the team are used to working flexibly and remotely.

Key responsibilities

  • Maintain and optimise the Security platform, including configuring EDR policies, tuning SIEM rules, and optimising the system for performance.
  • Monitor for security threats, analyse alerts, and respond to incidents using security tools; conduct vulnerability scans and support remediation and risk mitigation efforts.
  • Lead and participate in incident response efforts, conducting root cause analysis and developing runbooks for incident handling.
  • Oversee WAF, DDoS, VPN, and perimeter firewalls.
  • Manage Email and Web Security Gateways.
  • Maintain security certificates, encryption keys, and IDS/IPS systems.
  • Perform security scanning and vulnerability management, taking proactive steps to reduce operational risk.

INFRASTRUCTURE & IDENTITY

  • Work with network engineers to implement posture management, including ICE/NAC segmentation, lateral movement control, and firewalls.
  • Work with the Endpoints team to administer MFA, SSO, PAM, MDM/MAM, and Conditional Access.
  • Manage Identity and Access Management (IAM) solutions.
  • Develop and deploy automation tools and scripts to streamline common IT Security Operations tasks.

COLLABORATION & GOVERNANCE

  • Collaborate with third-party penetration testers to identify, prioritise, and remediate security vulnerabilities.
  • Create detailed reports on detected threats, incidents, and response actions; document configurations, processes, and runbooks.
  • Keep well-informed of the latest cybersecurity trends, emerging threats, and updates.
  • Comply with all relevant legal and regulatory obligations including the Solicitors Regulation Authority (SRA) Standards, Regulations, and Principle.

Required experience

  • EDR – platform management, EDR policy configuration, and SIEM tuning.
  • Microsoft Security: Defender (ATP), Azure Security Centre, Entra ID, Intune, Conditional Access.
  • Next Gen firewalls: Palo Alto Prisma (preferred) or similar - configuration and management.
  • Email security: Mimecast, Exchange Online, DMARC, and email DLP (Tessian or equivalent).
  • Identity and Access Management: CyberArk, Entra ID, SSO, MFA, and PAM solutions.
  • SIEM tooling: Sentinel, Exabeam, Splunk, or equivalent.
  • Vulnerability management: Tenable or equivalent enterprise toolsets.
  • Scripting and automation: PowerShell (preferred), KQL, or similar.
  • Data Loss Prevention (DLP) solutions including MS Purview Compliance Manager.
  • Certified Information Systems Security Professional (CISSP), desirable.
  • CREST Practitioner Security Analyst (CPSA), desirable.
  • Palo Alto Networks Certified Security Operations Professional, desirable.
  • CEH, OSCP, SANS, or ISACA certifications are also welcomed.

*where a level of experience is indicated, this is a guideline only and represents the amount of time we would usually expect a candidate to accumulate the requisite level of experience. This does not preclude applications from candidates with more or less experience.

Security Engineer employer: Kennedys Law LLP

At Kennedys, we pride ourselves on being an exceptional employer, offering a dynamic work environment where innovation and collaboration thrive. As a Security Engineer in our newly established SecOps team, you will have the opportunity to work with cutting-edge technology while contributing to our mission of enhancing security across our global operations. We foster a culture of continuous learning and professional growth, providing employees with the resources and support needed to excel in their careers, all within the vibrant settings of London and Chelmsford.

Kennedys Law LLP

Contact Detail:

Kennedys Law LLP Recruiting Team

StudySmarter Expert Advice🀫

We think this is how you could land Security Engineer

✨Tip Number 1

Network, network, network! Get out there and connect with people in the industry. Attend meetups, webinars, or even just chat with folks on LinkedIn. You never know who might have a lead on your dream Security Engineer role!

✨Tip Number 2

Show off your skills! Create a portfolio or GitHub repository showcasing your projects, scripts, or any security solutions you've developed. This gives potential employers a tangible look at what you can do, especially in a tech-heavy role like this.

✨Tip Number 3

Prepare for interviews by brushing up on common security scenarios and incident response strategies. Practice articulating your thought process and how you tackle challenges. Remember, they want to see how you think as much as what you know!

✨Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining our team at Kennedys!

We think you need these skills to ace Security Engineer

EDR platform management
SIEM tuning
Microsoft Security: Defender (ATP)
Azure Security Centre
Entra ID
Intune
Conditional Access

Some tips for your application 🫑

Tailor Your CV:Make sure your CV is tailored to the Security Engineer role. Highlight your experience with EDR, SIEM, and any relevant certifications. We want to see how your skills align with what we're looking for!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to our SecOps team. Keep it concise but impactful – we love a good story!

Showcase Your Technical Skills:Don’t hold back on showcasing your technical skills in your application. Mention specific tools and technologies you've worked with, like Microsoft Security or Palo Alto firewalls. We’re keen to see your hands-on experience!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of applications and ensures you get all the updates directly from us. Plus, it’s super easy!

How to prepare for a job interview at Kennedys Law LLP

✨Know Your Security Tools

Familiarise yourself with the specific security tools mentioned in the job description, like EDR platforms and SIEM systems. Be ready to discuss your experience with these tools and how you've used them to manage security threats or incidents.

✨Showcase Your Incident Response Skills

Prepare examples of past incidents you've managed, focusing on your role in the response and any root cause analysis you conducted. Highlight how you developed runbooks or processes that improved incident handling.

✨Understand Zero-Trust Principles

Since the role involves transitioning to a zero-trust model, brush up on what this means in practice. Be prepared to discuss how you would implement zero-trust strategies and the benefits they bring to an organisation's security posture.

✨Stay Updated on Cybersecurity Trends

Demonstrate your passion for cybersecurity by discussing recent trends or emerging threats. This shows you're proactive and committed to staying informed, which is crucial for a Security Engineer role.