IT Security Engineer

Job Locations UK-Basingstoke | UK-London
Posted Date 3 hours ago(08/10/2026 15:51)
Job ID
2026-1577
# of Openings
1
Category
Business support

Overview

The Security Engineer is a core member of the Security team, responsible for protecting the organisation's technology environment through proactive security monitoring, incident response, vulnerability management, and identity & access governance. They share responsibility across all security domains, operate a named on-call rota as the primary interface to the external SOC, and provide mutual peer backup. Each Security Engineer also owns formal responsibility for Vulnerability & Compliance and Identity & Access Management as defined disciplines.

Responsibilities

Security Operations

  • Monitor the SIEM platform and security tooling daily - triaging alerts, investigating anomalies, and escalating confirmed threats.
  • Act as the named internal interface to the external SOC - receiving escalations via the on-call rota, making incident response decisions, and providing the SOC with updated detection requirements.
  • Lead incident response for confirmed security events - coordinating containment, remediation, and recovery.
  • Own and manage Defender for Endpoint / XDR and Defender for Cloud Apps - maintaining configuration, reviewing alerts, and tuning detection policies.
  • Manage SIEM rule sets - adding new detection use cases, tuning existing rules, and reviewing rule coverage.

 

Vulnerability & Compliance

  • Own and operate the vulnerability management programme - running regular scanning, triaging findings, and tracking remediation to SLA.
  • Manage patching governance oversight - ensuring the organisation's patch management process is followed and exceptions are documented.
  • Maintain alignment with compliance frameworks - Cyber Essentials, ISO 27001, or equivalent.
  • Own Purview Compliance - maintaining audit log policies, eDiscovery configuration, and retention policies.

 

Identity & Access Management

  • Own the organisation's Identity & Access Management discipline - including Entra ID, Privileged Identity Management (PIM), and access governance.
  • Monitor the joiner/mover/leaver (JML) process - ensuring accounts are provisioned, modified, and deprovisioned accurately and on time.
  • Run and manage access reviews and access certification cycles - enforcing least privilege.
  • Manage privileged accounts - ensuring all privileged access is logged, reviewed, and time-bound where possible.

 

AI & Technology Governance (Security Input)

  • Review new AI tool requests from a security risk perspective - assessing data handling, access scoping, and prompt injection risk.
  • Ensure AI tools approved for use are correctly scoped and monitored; feed AI-related security findings into the risk register.

At our firm, Diversity, Equity and Inclusion is a priority and at the heart of everything we do. We actively want to attract a diverse workforce and welcome applications from everyone, from all backgrounds. We are committed to promoting an inclusive culture where everyone can be their full selves and experience being seen and heard. You can find out more about our firm’s commitment, initiatives and Pennclusion committees here.

 

We ensure that there are equal opportunities and treatment for all job applicants and employees, at all stages of the recruitment process and employment, regardless of age, gender reassignment, marriage or civil partnership, pregnancy and maternity, disability, race (including colour, nationality, ethnic or national origin), religion or belief, sex, sexual orientation, gender identity, gender expression and social background. We aim to provide adjustments for people who have a disability, long-term health condition (including mental health) or neurodiversity. If you would like to request an adjustment, please contact Sam.Austin@penningtonslaw.com

Essential & Desirable Criteria

Essential:

  • Hands-on experience with SIEM platforms - alert triage, rule management, and investigation (Microsoft Sentinel, Splunk, or equivalent)
  • Practical experience with Defender products - Defender for Endpoint, Defender for Cloud Apps, Defender for Identity
  • Vulnerability management experience - scanning, triage, and remediation tracking
  • Identity & access management knowledge - Entra ID / Azure AD, conditional access, PIM, access reviews
  • Incident response experience - containment, investigation, and remediation in a real-world environment
  • Minimum 2–3 years in a security operations or cyber security role
  • Experience responding to real security incidents
  • Experience with vulnerability management in an enterprise environment
  • Track record of working with IAM systems in a governance or operational capacity
  • Vigilant and detail-oriented - security threats are often subtle and require sustained attention
  • Calm and structured under pressure - able to follow an incident response process during a live security event
  • Collaborative with the Cloud Platform Specialist - understands that security and platform administration are interdependent
  • Communicates security risk clearly - translates technical findings into risk language the business can understand
  • Takes ownership - does not wait to be told to act when a threat is identified

 

Desirable:

 

  • Security certifications: SC-200, CompTIA Security+, CySA+, CEH, or equivalent
  • Experience with Purview Compliance workloads (eDiscovery, audit logs, retention)
  • Familiarity with ISO 27001, Cyber Essentials Plus, or NIST CSF
  • Experience working with or managing an external SOC relationship
  • Experience in a peer-model security team or SOC environment
  • Exposure to a regulated industry with compliance requirements
  • Interest in emerging threats and staying current with the security landscape

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed