IT Security Engineer
Basingstoke - UK
Job Summary
The Security Engineer is a core member of the Security team responsible for protecting the organisations technology environment through proactive security monitoring incident response vulnerability management and identity & access governance. They share responsibility across all security domains operate a named on-call rota as the primary interface to the external SOC and provide mutual peer backup. Each Security Engineer also owns formal responsibility for Vulnerability & Compliance and Identity & Access Management as defined disciplines.
Security Operations
- Monitor the SIEM platform and security tooling daily - triaging alerts investigating anomalies and escalating confirmed threats.
- Act as the named internal interface to the external SOC - receiving escalations via the on-call rota making incident response decisions and providing the SOC with updated detection requirements.
- Lead incident response for confirmed security events - coordinating containment remediation and recovery.
- Own and manage Defender for Endpoint / XDR and Defender for Cloud Apps - maintaining configuration reviewing alerts and tuning detection policies.
- Manage SIEM rule sets - adding new detection use cases tuning existing rules and reviewing rule coverage.
Vulnerability & Compliance
- Own and operate the vulnerability management programme - running regular scanning triaging findings and tracking remediation to SLA.
- Manage patching governance oversight - ensuring the organisations patch management process is followed and exceptions are documented.
- Maintain alignment with compliance frameworks - Cyber Essentials ISO 27001 or equivalent.
- Own Purview Compliance - maintaining audit log policies eDiscovery configuration and retention policies.
Identity & Access Management
- Own the organisations Identity & Access Management discipline - including Entra ID Privileged Identity Management (PIM) and access governance.
- Monitor the joiner/mover/leaver (JML) process - ensuring accounts are provisioned modified and deprovisioned accurately and on time.
- Run and manage access reviews and access certification cycles - enforcing least privilege.
- Manage privileged accounts - ensuring all privileged access is logged reviewed and time-bound where possible.
AI & Technology Governance (Security Input)
- Review new AI tool requests from a security risk perspective - assessing data handling access scoping and prompt injection risk.
- Ensure AI tools approved for use are correctly scoped and monitored; feed AI-related security findings into the risk register.
At our firm Diversity Equity and Inclusion is a priority and at the heart of everything we do. We actively want to attract a diverse workforce and welcome applications from everyone from all backgrounds. We are committed to promoting an inclusive culture where everyone can be their full selves and experience being seen and heard. You can find out more about our firms commitment initiatives and Pennclusion committees here.
We ensure that there are equal opportunities and treatment for all job applicants and employees at all stages of the recruitment process and employment regardless of age gender reassignment marriage or civil partnership pregnancy and maternity disability race (including colour nationality ethnic or national origin) religion or belief sex sexual orientation gender identity gender expression and social background. We aim to provide adjustments for people who have a disability long-term health condition (including mental health) or neurodiversity. If you would like to request an adjustment please contact
Essential:
- Hands-on experience with SIEM platforms - alert triage rule management and investigation (Microsoft Sentinel Splunk or equivalent)
- Practical experience with Defender products - Defender for Endpoint Defender for Cloud Apps Defender for Identity
- Vulnerability management experience - scanning triage and remediation tracking
- Identity & access management knowledge - Entra ID / Azure AD conditional access PIM access reviews
- Incident response experience - containment investigation and remediation in a real-world environment
- Minimum 23 years in a security operations or cyber security role
- Experience responding to real security incidents
- Experience with vulnerability management in an enterprise environment
- Track record of working with IAM systems in a governance or operational capacity
- Vigilant and detail-oriented - security threats are often subtle and require sustained attention
- Calm and structured under pressure - able to follow an incident response process during a live security event
- Collaborative with the Cloud Platform Specialist - understands that security and platform administration are interdependent
- Communicates security risk clearly - translates technical findings into risk language the business can understand
- Takes ownership - does not wait to be told to act when a threat is identified
Desirable:
- Security certifications: SC-200 CompTIA Security CySA CEH or equivalent
- Experience with Purview Compliance workloads (eDiscovery audit logs retention)
- Familiarity with ISO 27001 Cyber Essentials Plus or NIST CSF
- Experience working with or managing an external SOC relationship
- Experience in a peer-model security team or SOC environment
- Exposure to a regulated industry with compliance requirements
- Interest in emerging threats and staying current with the security landscape
Required Experience:
IC
About Company
Penningtons Manches Cooper is a top ranked UK and international law firm, delivering imaginative and incisive legal advice to commercial and private clients.