Security & Infrastructure Engineer
Indexed description
Business Unit: Corporate - Information Technology
Reports to: Sr. Manager, Global Security & Infrastructure
Location: Home office based with a hybrid working arrangement. Employee must be within a commutable distance of our office in Chalfont St Peter, Buckinghamshire, with travel to the office required when necessary.
Mgmt Level: Individual Contributor
About the Role
We are seeking a hands-on Security & Infrastructure Engineer to support and improve our cloud, identity, endpoint and security operations capabilities.
This is not a pure SOC role. The successful candidate will work across Microsoft cloud security, endpoint management, vulnerability management, infrastructure support and compliance activities, helping to strengthen the organisation's security posture while ensuring core services remain secure, reliable and well managed.
This position includes occasional out-of-hours patch management and maintenance activities.
Key Responsibilities
Identity & Access Management
- Administer Microsoft Entra ID, including users, groups, enterprise applications and identity-related configurations.
- Support Conditional Access, MFA, SSO and identity security controls.
- Assist with identity governance, access reviews, privileged access controls and user lifecycle processes.
- Troubleshoot authentication, access and account-related issues across Microsoft cloud services.
Endpoint & Device Management
- Administer Microsoft Intune and Mobile Device Management (MDM) policies across corporate devices.
- Manage device compliance, configuration profiles, security baselines and application deployment.
- Support endpoint lifecycle activities, including enrolment, configuration, troubleshooting and remediation.
- Work closely with IT and security colleagues to improve endpoint hardening and operational consistency.
- Perform server and endpoint patching, including out-of-hours maintenance where required.
Security Operations & EDR
- Support the management and optimisation of Endpoint Detection and Response (EDR) platforms, including Microsoft Defender and similar technologies.
- Investigate security alerts, validate findings and assist with incident response activities.
- Contribute to improvements in monitoring, alert handling, endpoint protection and security control effectiveness.
- Maintain clear documentation for operational processes and security procedures.
Vulnerability Management
- Support vulnerability scanning, triage, prioritisation and remediation tracking.
- Work with infrastructure, application and business stakeholders to drive timely remediation of security weaknesses.
- Validate remediation actions and help maintain accurate vulnerability reporting.
- Support external penetration testing activities and track remediation actions through to completion.
Cloud, Microsoft 365 & Infrastructure
- Support Azure administration and cloud security improvement initiatives.
- Assist with Microsoft 365 administration, security configuration and operational support.
- Contribute to infrastructure projects covering endpoints, identity, networking, resilience and platform improvements.
- Provide technical escalation support for security and infrastructure-related issues.
Governance, Risk & Compliance
- Assist with ISO 27001, SOC 2 and similar audit and compliance activities.
- Support evidence collection, access reviews, control validation and audit remediation actions.
- Contribute to security standards, procedures, operational checklists and technical documentation.
- Support vendor security reviews and third-party risk management activities where required.
Automation & Continuous Improvement
- Use PowerShell and other scripting approaches to automate repeatable operational tasks.
- Identify opportunities to simplify processes, improve control visibility and reduce manual effort.
- Create and maintain technical documentation, runbooks and knowledge articles.
- Support ongoing improvements in security maturity, operational resilience and service reliability.
Qualifications & Experience
Essential
- Previous experience in a Security Engineer, Infrastructure Engineer, Systems Administrator or similar technical role.
- Strong working knowledge of Microsoft Entra ID and Microsoft 365 administration.
- Hands-on experience with Microsoft Intune, MDM and endpoint management.
- Experience working with EDR or endpoint security platforms.
- Experience supporting vulnerability management processes and remediation tracking.
- Good understanding of cloud, endpoint, identity and access management concepts.
- Ability to troubleshoot technical issues across security and infrastructure environments.
- Strong communication skills and the ability to work effectively with both technical and non-technical stakeholders.
- Strong documentation skills and a practical, process-driven approach to operational improvement.
Desirable
- Azure administration or cloud security experience.
- Networking knowledge, including firewalls, VPNs, DNS, routing and secure remote access.
- PowerShell scripting or automation experience.
- Exposure to ISO 27001, SOC 2, Cyber Essentials, NIST or similar security frameworks.
- Penetration testing, vulnerability assessment or remediation experience.
- Experience supporting audits, evidence collection, access reviews or security questionnaires.
- Relevant certifications such as Security+, AZ-104, SC-300, SC-200, MD-102, CISSP Associate or similar.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search