Senior Security Engineer

23 hours ago


Slough Berkshire, United Kingdom Space NK Full time

If you love beauty, you're in the right place. As the ultimate curator of over 100 of the most in-demand, highly innovative and boundary-pushing beauty brands, we are the go-to destination for worldwide beauty discovery. Together through our neighbourhood stores, online presence and loyalty scheme, Space NK has built a flourishing community in which to discover beauty. The customer is at the heart of everything we do, and we will always endeavour to offer everything they need to help them explore, experiment, and enjoy our brands. About The Role Space NK operates a hybrid environment across Microsoft Azure, corporate offices, datacentres, and a large UK retail footprint. As a Security Engineer, you will design, implement, and operate security controls across cloud platforms, identity systems, endpoints, servers, and business applications. You will support the organisation's security posture by ensuring that identity, cloud security, data protection, threat detection, and compliance controls are consistently applied and continuously improved. This role is technical and hands-on, with architectural influence. It requires close collaboration with Network Engineering, Infrastructure, Cloud, and Application teams to ensure secure-by-design solutions across the entire ecosystem. Your Role As a Security Engineer, you will be responsible for owning and operating the security controls that protect Space NK's identity, cloud, and on-premises environments. You will define and maintain security standards, enhance detection capabilities, harden platforms, and support incident response. You will lead improvements across authentication, authorisation, cloud posture, endpoint security, vulnerability management, and compliance frameworks. You will work closely with Network Engineering, who operate routing, switching, firewalls, VPNs, and connectivity. Your responsibility is to define the security requirements, validate secure configurations, and ensure Zero Trust and compliance controls are met — while Network Engineering implements the network infrastructure itself. This role bridges strategy and technical execution: shaping identity security, strengthening Azure cloud posture, enhancing monitoring and detection capabilities, advising on architecture, and maintaining a secure foundation for all business platforms. Key Responsibilities Hybrid Security Architecture & Governance Design and implement security controls across Azure cloud services, on-prem servers, and SaaS applications. Define and maintain security baselines, hardening standards, and cloud security benchmarks (Microsoft CSB, CIS, NIST). Govern and enforce Azure Policy, Defender for Cloud, and platform-level security controls. Participate in design and architecture reviews to ensure secure-by-design deployments. Maintain security documentation, operational runbooks, standards, and policy artefacts. Support risk assessments, penetration test remediation, and threat modelling activities. Identity & Access Security Define and maintain identity security standards for Microsoft Entra ID and Active Directory Domain Services. Provide security requirements for Conditional Access, MFA, SSO, passwordless authentication, and identity governance, implemented by the IAM teams. Partner with IAM/Infrastructure teams to ensure privileged access (PIM), RBAC models, and least-privilege designs meet security requirements. Harden identity infrastructure including domain controllers, authentication protocols (Kerberos/NTLM), secure LDAP, and hybrid identity components. Monitor identity-related security signals (Identity Protection, risky users/sign-ins) and support investigation of identity-based attacks. Validate secure delegation models, access review processes, and identity lifecycle controls defined by IAM. Threat Detection, Monitoring & Incident Response Own and operate SIEM and SOAR tooling, including Microsoft Sentinel, Defender XDR, Identity Protection, and threat analytics. Develop and refine detection rules, correlation logic, threat hunting use cases, and behavioural analytics. Investigate and support incident response for identity compromise, endpoint attacks, Azure cloud events, or server breaches. Integrate telemetry from Azure, endpoints, identity platforms, and security tools. Produce incident reports, RCA documentation, and post-incident improvement plans. Coordinate with SOC teams or third-party providers when required. Endpoint, Server, and Infrastructure Security Implement CIS/NIST-aligned hardening across Windows Server, domain controllers, virtual machines, and Azure workloads. Deploy and manage endpoint protection and EDR platforms (e.g., Microsoft Defender for Endpoint). Enforce secure baselines across virtualisation platforms (VMware/Hyper-V) and Azure IaaS services. Partner with Infrastructure teams on patch governance, vulnerability remediation, and secure configuration management. Support security oversight of server migrations, consolidations, and platform modernisation. Data Protection & Encryption Operate Azure Key Vault and certificate lifecycle management via AD CS/PKI. Implement data classification, sensitivity labels, retention controls, and DLP using Microsoft Purview/AIP. Enforce encryption-in-transit and at-rest across Azure and on-prem environments. Support GDPR, PCI DSS, and organisational data protection requirements. Azure Cloud Security Deliver cloud-native security configuration for Azure Landing Zones, subscriptions, and resource groups. Manage cloud security posture using Defender for Cloud and Azure-native CSPM controls. Configure secure connectivity to Azure services (Private Endpoints, Service Endpoints, segmentation boundaries). Collaborate with Network Engineering to validate secure ExpressRoute, VPN, and firewall configurations — Network Engineering operates the underlying infrastructure. Ensure consistent security policy enforcement across Azure workloads. Compliance, Audit & Risk Management Support ISO 27001, PCI DSS, Cyber Essentials Plus, and NIST compliance activities. Prepare audit evidence, configuration exports, policy documentation, and control validation artefacts. Maintain risk registers, track remediation progress, and support risk assessments. Participate in CAB/change management from a security perspective. Support DR/BCP planning from a security controls perspective. Collaboration & Governance Work closely with Network Engineering on segmentation requirements, firewall policy governance, and secure architecture reviews. Partner with Infrastructure, Cloud, and Application teams to ensure secure deployments. Provide security guidance across projects, deployments, and operational teams. Help raise security awareness across the technology organisation. Essential Skills & Experience Strong experience securing Azure environments, including Defender for Cloud, Conditional Access, and identity protection tooling. Deep knowledge of Microsoft Entra ID, AD DS, MFA, PIM, RBAC, and hybrid identity security. Hands-on experience with SIEM (Sentinel), SOAR, EDR (MDE), CSPM, and vulnerability management tools. Experience securing Windows Server, PKI/ADCS, domain controllers, and virtualisation environments. Practical understanding of Zero Trust security principles and secure-by-design. Strong understanding of PCI DSS, ISO 27001, Cyber Essentials Plus, and NIST controls. Ability to perform forensic investigation, log analysis, and threat triage. Desirable Skills Awareness of AWS security fundamentals (GuardDuty, Security Hub, KMS, IAM Identity Center). Basic understanding of AWS hybrid connectivity and identity integrations (advantageous but not required). DevSecOps and secure CI/CD practices. IaC security automation (Terraform, Bicep). Container security (AKS) and SaaS application security. PowerShell/Python scripting for automation. Please note that only successful candidates will be contacted. All applicants must have the right to live and work in the UK. If you want to find out more about us, what it is like to work for us, all about our benefits, and our pledges on Diversity, Inclusion and Belonging, please visit our website. Space NK are an equal opportunities employer. How We Will Use Your Information We will use the information you provide to us with your job application to help us process your application for the specific job you have applied for. If you apply speculatively, we will process your application for the job/relevant business area that you detail within your email. Please note that our current system does not use an automated filtering system. All applications made via the website, through a third-party website or in-store will be kept on file for a period of 12 months. This information will be retained and used to assess your suitability to similar positions that may arise in the future, or if the initial vacancy becomes live again during the 12-month period. If you would prefer us to not hold your information on file/ you wish to be 'forgotten' if you are not offered a position with Space NK, please email your 'right to be forgotten' to our recruitment email address with RIGHT TO BE FORGOTTEN as the title of the email. We will always inform you when we have deleted your application details, otherwise we will treat your application as consent to us holding this information.



  • Slough, Berkshire, United Kingdom Quant Capital Full time

    Senior IT Security Engineer – Windows, Automation, Endpoint Security London – Hybrid Industry Leading Compensation Quant Capital is partnered with a leading trading firm looking to hire a Senior IT Security Engineer to strengthen its global security posture. This sits within a high-performing engineering group and suits someone who can take ownership,...


  • Slough, Berkshire, United Kingdom Workonomics Full time

    Company | SaaS, Product, B2B2C Size | 600 people globally, 60 in London Role | Security Engineer Level | Senior Areas | Security, Platform, GenAI, R&D Skills | AWS / GCP, Python / Node.js / Go, K8s, Terraform Based | Zone 1, London Hybrid | 2-3 days a week in-office Offer | £100-120k + bonus + RSUs + 4.5 day work week Hi Workonomics are partnering with a...


  • Slough, Berkshire, United Kingdom Insite Risk Management Full time

    About the job Position Description: Security Technology Intermediate Engineer The Security Technology Intermediate Engineer will utilize specialized knowledge to support the deployment, integration, maintenance, and upgrading of physical security systems. In collaboration with the Managing Director of Security Technology and Security Consulting team, the...


  • Slough, Berkshire, United Kingdom Cofide Full time

    Cofide is an early-stage startup on a mission to revolutionise how enterprises secure workloads across any cloud environment. By focusing on the foundational layer of identity, we’re building solutions based on open standards like SPIFFE and OAuth that make Zero Trust architectures practical and achievable for organisations of any size. We believe that...


  • Slough, Berkshire, United Kingdom 55 Exec Search Full time

    Senior OT / CNI Security Architect UK-based | Remote with client travel | Must be eligible for UK Gov Security Clearance We're seeking a Senior OT Security Architect to join a fast-paced consulting engagement within a complex, high-impact technology environment. The Senior OT / CNI Security Architect will help secure some of the most critical environments in...


  • Slough, Berkshire, United Kingdom McGregor Boyall Full time

    Cloud Security Engineer/Developer (AWS) - Node.js/NestJS and REST API - Authentication (Auth0, Ping Identity) Permanent, up to £88,000 + package ***Hybrid - 3 days office Leading financial services client is seeking a Senior Cloud Security Engineer and help shape their cybersecurity in a fast-paced, global environment. Key Responsibilities: Design and...


  • Slough, Berkshire, United Kingdom Lendable Full time

    About Lendable Lendable is on a mission to build the world's best technology to help people get credit and save money. We're building one of the world's leading fintech companies and are off to a strong start: One of the UK's newest unicorns with a team of just over 600 people Among the fastest-growing tech companies in the UK Profitable since 2017 Backed by...


  • Slough, Berkshire, United Kingdom Advanced Resource Managers Full time

    Senior Infrastructure Engineer 6 month contract Based in Reading Offering £88ph Inside IR35 Do you have experience with virtualisation platforms (VMware, Hyper-V, etc.)? Do you have experience with cloud platforms (AWS, Azure, etc.)? Do you want to work with an industry-leading company? If your answer to these is yes, then this could be the role for you! As...


  • Slough, Berkshire, United Kingdom Stott and May Full time

    Job Description Role Title: Microsoft Security Engineer Location: London - Hybrid (2–3 days in office) Day Rate: £586.50 (Inside IR35) Duration: 6 months Role Overview We are looking for a proactive Microsoft Security Engineer to protect digital assets and strengthen the organisation’s security posture. The role involves working with...


  • Slough, Berkshire, United Kingdom Fnality Full time

    Introduction Here at Fnality, we are powering the future of finance, together: combining best in class technology with free-flowing creativity, and expertise that can make business better for everyone. With you on our side, we’ll be setting new ones every day. Fnality Services is central to each Fnality Payment System’s (FnPS) effective and resilient...