Security Engineer

Security Engineer

Full-Time 55000 - 65000 £ / year (est.) No working from home possible
Kennedys

At a Glance

  • Tasks: Join our SecOps team to implement and maintain top-notch security measures.
  • Company: Kennedys, a leading firm with a global IT team.
  • Benefits: Flexible working, competitive salary, and opportunities for professional growth.
  • Other info: Collaborative environment focused on innovation and continuous learning.
  • Why this job: Make a real impact in cybersecurity while working with cutting-edge technologies.
  • Qualifications: Experience in EDR, SIEM, and security tools; certifications are a plus.

The predicted salary is between 55000 - 65000 £ per year.

Kennedys is looking for a Security Engineer to join Kennedys, who will be a vital member of our newly established SecOps team, reporting directly to the IT Security Manager. This position is crucial in implementing and maintaining robust security measures across our technology landscape, as well as managing incident response. The role involves developing, implementing, and sustaining security solutions designed to protect our systems against constantly evolving cyber threats, with a focus on transitioning to a zero-trust operating model. The Security Engineer will work collaboratively across IT functions, spearhead key security initiatives, and play a pivotal role in enhancing our overall security posture. The role will also support the firm in its pursuit of ISO 27001 certification and the implementation of CIS controls.

Team Kennedys' IT team is responsible for the maintenance of IT systems and security across the firm, including its portfolio of managed bespoke and off-the-shelf applications. This role will work across all IT functions and, in the case of broader projects, occasionally with other business functions within the firm. The majority of the global IT team are based in London and Chelmsford, although some staff are based in other UK and non-UK offices. As a team that provides a truly global service, the team are used to working flexibly and remotely.

Key Responsibilities

  • Maintain and optimise the Security platform, including configuring EDR policies, tuning SIEM rules, and optimising the system for performance.
  • Monitor for security threats, analyse alerts, and respond to incidents using security tools; conduct vulnerability scans and support remediation and risk mitigation efforts.
  • Lead and participate in incident response efforts, conducting root cause analysis and developing runbooks for incident handling.
  • Oversee WAF, DDoS, VPN, and perimeter firewalls.
  • Manage Email and Web Security Gateways.
  • Maintain security certificates, encryption keys, and IDS/IPS systems.
  • Perform security scanning and vulnerability management, taking proactive steps to reduce operational risk.

INFRASTRUCTURE & IDENTITY

  • Work with network engineers to implement posture management, including ICE/NAC segmentation, lateral movement control, and firewalls.
  • Work with the Endpoints team to administer MFA, SSO, PAM, MDM/MAM, and Conditional Access.
  • Manage Identity and Access Management (IAM) solutions.
  • Develop and deploy automation tools and scripts to streamline common IT Security Operations tasks.

COLLABORATION & GOVERNANCE

  • Collaborate with third-party penetration testers to identify, prioritise, and remediate security vulnerabilities.
  • Create detailed reports on detected threats, incidents, and response actions; document configurations, processes, and runbooks.
  • Keep well-informed of the latest cybersecurity trends, emerging threats, and updates.
  • Comply with all relevant legal and regulatory obligations including the Solicitors Regulation Authority (SRA) Standards, Regulations, and Principle.

Required Experience

  • EDR – platform management, EDR policy configuration, and SIEM tuning.
  • Microsoft Security: Defender (ATP), Azure Security Centre, Entra ID, Intune, Conditional Access.
  • Next-Gen firewalls: Palo Alto Prisma (preferred) or similar – configuration and management.
  • Email security: Mimecast, Exchange Online, DMARC, and email DLP (Tessian or equivalent).
  • Identity and Access Management: CyberArk, Entra ID, SSO, MFA, and PAM solutions.
  • SIEM tooling: Sentinel, Exabeam, Splunk, or equivalent.
  • Vulnerability management: Tenable or equivalent enterprise toolsets.
  • Scripting and automation: PowerShell (preferred), KQL, or similar.
  • Data Loss Prevention (DLP) solutions including MS Purview Compliance Manager.
  • Certified Information Systems Security Professional (CISSP), desirable.
  • CREST Practitioner Security Analyst (CPSA), desirable.
  • Palo Alto Networks Certified Security Operations Professional, desirable.
  • CEH, OSCP, SANS, or ISACA certifications are also welcomed.

*Where a level of experience is indicated, this is a guideline only and represents the amount of time we would usually expect a candidate to accumulate the requisite level of experience. This does not preclude applications from candidates with more or less experience.

Security Engineer employer: Kennedys

At Kennedys, we pride ourselves on being an exceptional employer, offering a dynamic work environment where innovation and collaboration thrive. Our newly established SecOps team is at the forefront of cybersecurity, providing employees with unique opportunities for professional growth and development while working towards ISO 27001 certification. With a flexible approach to remote work and a commitment to employee well-being, Kennedys fosters a culture that values diversity, inclusivity, and continuous learning, making it an ideal place for passionate Security Engineers to make a meaningful impact.

Kennedys

Contact Details:

Kennedys Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Security Engineer

Tip Number 1

Network, network, network! Get out there and connect with folks in the industry. Attend meetups, webinars, or even online forums. The more people you know, the better your chances of hearing about job openings before they’re even advertised.

Tip Number 2

Don’t just apply blindly! Tailor your approach for each role. Research Kennedys and understand their security needs. When you reach out, mention specific projects or initiatives they’re involved in that excite you. Show them you’re genuinely interested!

Tip Number 3

Prepare for interviews like it’s a big game day. Brush up on your technical skills and be ready to discuss your experience with EDR, SIEM, and other tools mentioned in the job description. Practice common interview questions and have your own questions ready to show you’re engaged.

Tip Number 4

Apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, it shows you’re proactive and serious about joining the team at Kennedys. Don’t miss out on this opportunity!

We think you need these skills to ace Security Engineer

EDR platform management
SIEM tuning
Microsoft Security: Defender (ATP)
Azure Security Centre
Entra ID
Intune
Conditional Access

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Security Engineer role. Highlight relevant experience and skills that match the job description, like your expertise in EDR management or SIEM tuning. We want to see how you can contribute to our SecOps team!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about cybersecurity and how your background aligns with our goals at Kennedys. Don’t forget to mention any specific projects or achievements that showcase your skills.

Showcase Your Technical Skills:In your application, be sure to highlight your technical skills, especially those mentioned in the job description, like Microsoft Security tools or vulnerability management. We love seeing candidates who are up-to-date with the latest cybersecurity trends!

Apply Through Our Website:We encourage you to apply through our website for a smoother process. It helps us keep track of your application and ensures you’re considered for the role. Plus, it’s super easy to do!

How to prepare for a job interview at Kennedys

Know Your Security Tools

Familiarise yourself with the specific security tools mentioned in the job description, like EDR platforms and SIEM systems. Be ready to discuss your experience with these tools and how you've used them to manage security incidents or vulnerabilities.

Showcase Your Collaboration Skills

Since the role involves working across IT functions and with third-party testers, prepare examples of how you've successfully collaborated in past roles. Highlight any projects where teamwork was essential to achieving security goals.

Stay Updated on Cybersecurity Trends

Demonstrate your knowledge of the latest cybersecurity threats and trends during the interview. This shows that you're proactive and committed to staying informed, which is crucial for a Security Engineer.

Prepare for Scenario-Based Questions

Expect scenario-based questions related to incident response and vulnerability management. Practice articulating your thought process and decision-making in these situations, as it will showcase your problem-solving skills and technical expertise.