At a Glance
- Tasks: Join our SecOps team to enhance security measures and manage incident responses.
- Company: Kennedys, a forward-thinking firm focused on robust IT security.
- Benefits: Flexible working, competitive salary, and opportunities for professional growth.
- Other info: Collaborative environment with a focus on continuous learning and development.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
- Qualifications: Experience in EDR, SIEM, and cloud security tools is preferred.
The predicted salary is between 60000 - 80000 £ per year.
Kennedys is looking for a Security Engineer to join Kennedys, who will be a vital member of our newly established SecOps team, reporting directly to the IT Security Manager. This position is crucial in implementing and maintaining robust security measures across our technology landscape, as well as managing incident response. The role involves developing, implementing, and sustaining security solutions designed to protect our systems against constantly evolving cyber threats, with a focus on transitioning to a zero‑trust operating model. The Security Engineer will work collaboratively across IT functions, spearhead key security initiatives, and play a pivotal role in enhancing our overall security posture. The role will also support the firm in its pursuit of ISO 27001 certification and the implementation of CIS controls.
Team Kennedys' IT team is responsible for the maintenance of IT systems and security across the firm, including its portfolio of managed bespoke and off‑the‑shelf applications. This role will work across all IT functions and, in the case of broader projects, occasionally with other business functions within the firm. The majority of the global IT team are based in London and Chelmsford, although some staff are based in other UK and non‑UK offices. As a team that provides a truly global service, the team are used to working flexibly and remotely.
Key responsibilities
- Maintain and optimise the Security platform, including configuring EDR policies, tuning SIEM rules, and optimising the system for performance.
- Monitor for security threats, analyse alerts, and respond to incidents using security tools; conduct vulnerability scans and support remediation and risk mitigation efforts.
- Lead and participate in incident response efforts, conducting root cause analysis and developing runbooks for incident handling.
- Oversee WAF, DDoS, VPN, and perimeter firewalls.
- Manage Email and Web Security Gateways.
- Maintain security certificates, encryption keys, and IDS/IPS systems.
- Perform security scanning and vulnerability management, taking proactive steps to reduce operational risk.
Infrastructure & Identity
- Work with network engineers to implement posture management, including ICE/NAC segmentation, lateral movement control, and firewalls.
- Work with the Endpoints team to administer MFA, SSO, PAM, MDM/MAM, and Conditional Access.
- Manage Identity and Access Management (IAM) solutions.
- Develop and deploy automation tools and scripts to streamline common IT Security Operations tasks.
Collaboration & Governance
- Collaborate with third‑party penetration testers to identify, prioritise, and remediate security vulnerabilities.
- Create detailed reports on detected threats, incidents, and response actions; document configurations, processes, and runbooks.
- Keep well‑informed of the latest cybersecurity trends, emerging threats, and updates.
- Comply with all relevant legal and regulatory obligations including the Solicitors Regulation Authority (SRA) Standards, Regulations, and Principles.
Required experience
- EDR – platform management, EDR policy configuration, and SIEM tuning.
- Microsoft Security: Defender (ATP), Azure Security Centre, Entra ID, Intune, Conditional Access.
- Next Gen firewalls: Palo Alto Prisma (preferred) or similar – configuration and management.
- Email security: Mimecast, Exchange Online, DMARC, and email DLP (Tessian or equivalent).
- Identity and Access Management: CyberArk, Entra ID, SSO, MFA, and PAM solutions.
- SIEM tooling: Sentinel, Exabeam, Splunk, or equivalent.
- Vulnerability management: Tenable or equivalent enterprise toolsets.
- Scripting and automation: PowerShell (preferred), KQL, or similar.
- Data Loss Prevention (DLP) solutions including MS Purview Compliance Manager.
- Certified Information Systems Security Professional (CISSP), desirable.
- CREST Practitioner Security Analyst (CPSA), desirable.
- Palo Alto Networks Certified Security Operations Professional, desirable.
- CEH, OSCP, SANS, or ISACA certifications are also welcomed.
Where a level of experience is indicated, this is a guideline only and represents the amount of time we would usually expect a candidate to accumulate the requisite level of experience. This does not preclude applications from candidates with more or less experience.
Kennedys is an equal opportunities employer and is committed to ensuring our recruitment processes are as inclusive as possible. We expect all employees to be aware of and comply with all relevant policies and procedures within their jurisdiction, including those relating to Information Security, Data Protection and Quality Management, refer any breach promptly to Risk & Compliance and to complete all mandatory training when requested.
Zero-Trust SecOps Engineer | Incident Response in Birmingham employer: Kennedys
Kennedys is an excellent employer, offering a dynamic work culture that values collaboration and professional growth. With a hybrid working policy, employees enjoy the flexibility of remote work while being part of a supportive team in Belfast, where opportunities for career advancement and skill development are abundant. The firm prioritises employee well-being and fosters an environment where proactive individuals can thrive in their legal careers.
StudySmarter Expert Advice🤫
We think this is how you could land Zero-Trust SecOps Engineer | Incident Response in Birmingham
✨Tip Number 1
Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even just grab a coffee with someone who works in SecOps. You never know who might have the inside scoop on job openings!
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, scripts, or any security tools you've developed. This gives potential employers a tangible look at what you can do, especially in a hands-on role like this.
✨Tip Number 3
Prepare for those interviews! Research Kennedys and understand their approach to security, especially around zero-trust models. Be ready to discuss how your experience aligns with their needs and how you can contribute to their security initiatives.
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re genuinely interested in joining the team at Kennedys.
We think you need these skills to ace Zero-Trust SecOps Engineer | Incident Response in Birmingham
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the role of Zero-Trust SecOps Engineer. Highlight your experience with EDR, SIEM, and any relevant certifications. We want to see how your skills align with our needs!
Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how you can contribute to our SecOps team. Keep it concise but impactful.
Showcase Your Technical Skills:In your application, don’t forget to mention specific tools and technologies you’ve worked with, like Microsoft Security or Palo Alto firewalls. We love seeing hands-on experience that matches our tech stack!
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy!
How to prepare for a job interview at Kennedys
✨Know Your Zero-Trust Principles
Make sure you understand the core concepts of a zero-trust operating model. Be ready to discuss how you would implement these principles in a real-world scenario, especially in relation to incident response and security measures.
✨Familiarise Yourself with Key Tools
Brush up on your knowledge of EDR platforms, SIEM tools, and vulnerability management systems mentioned in the job description. Being able to speak confidently about your experience with tools like Microsoft Defender or Palo Alto will impress the interviewers.
✨Prepare for Technical Questions
Expect technical questions that assess your problem-solving skills in security incidents. Practice articulating your thought process when responding to security threats or conducting root cause analysis, as this will showcase your analytical abilities.
✨Showcase Your Collaboration Skills
Since the role involves working across various IT functions, be prepared to discuss examples of how you've successfully collaborated with teams in the past. Highlight any experience you have with third-party penetration testers or cross-functional projects.