IT Security Operations Engineer (Infrastructure) - #2158360
Harvey Nash
Role: IT Security Operations Engineer (Infrastructure)
Location: Birmingham - Hybrid
Salary: £55,000
I’m looking for an IT Security Operations Engineer to join a Digital & Technology team and help protect technology, information and services from evolving cyber threats.
This is a hands-on security operations role focused on security monitoring, incident response, security tooling, vulnerability management, identity and access management, governance and continuous improvement.
THE ROLE
You’ll help keep systems secure, resilient and available, working closely with colleagues across IT and external security partners.
Security Monitoring & Incident Response
• Monitor security alerts across user devices, networks, cloud services and business systems
• Investigate suspicious activity, phishing emails, malware and compromised accounts
• Triage and investigate security incidents
• Take appropriate action to contain incidents and coordinate recovery with relevant IT teams
• Escalate serious incidents where required
• Maintain clear and accurate investigation and incident records
Security Tools & Controls
• Manage and maintain security tools including SIEM, Microsoft Defender, endpoint protection, email security and vulnerability scanning
• Review Microsoft 365, Azure and Entra ID security alerts and configurations
• Maintain security detection rules, dashboards and automated responses
• Support firewall, VPN, web filtering and wider network security controls
• Help ensure security tools and controls remain effective and appropriately configured
Vulnerability & Access Management
• Identify, assess and track system vulnerabilities and security weaknesses
• Work with technical teams to ensure security updates and remediation actions are completed
• Review privileged accounts, third-party access and inactive accounts
• Investigate unusual sign-in activity
• Support secure access controls and authentication processes
• Contribute to effective MFA and identity security practices
Governance, Reporting & Documentation
• Produce regular operational security reports, risk updates and incident summaries
• Maintain security procedures, incident response plans and technical documentation
• Support audits, compliance checks and evidence gathering
• Contribute to the development and maintenance of security policies and standards
Advice & Continuous Improvement
• Provide practical cyber security advice to employees and IT colleagues
• Support security awareness and phishing education activities
• Monitor emerging threats and assess their potential impact
• Recommend improvements to security tools, processes and configurations
• Liaise with security suppliers and managed service providers where required
• Contribute to the ongoing improvement of the organisation’s cyber security posture
WHAT WE’RE LOOKING FOR
We’re looking for someone with practical experience in cyber security operations, infrastructure security or a comparable technical role.
You’ll have experience of:
- Monitoring and investigating security alerts
- Investigating phishing, malware, compromised accounts and suspicious activity
- Using and maintaining SIEM, endpoint protection, email security and vulnerability-management tools
- Working with Microsoft 365, Azure and Entra ID security controls, alerts and identity-management capabilities
- Incident response, including triage, containment, escalation, recovery and accurate record keeping
- Vulnerability remediation and managing security weaknesses
- Access controls, privileged accounts, MFA and secure authentication practices
- Network security controls including firewalls, VPNs and web filtering
- Maintaining security documentation and producing clear operational reports
- Supporting audits, compliance activity and evidence gathering
- Assessing cyber risk and providing practical technical advice
- Working effectively with internal IT teams and external security providers
QUALIFICATIONS & PROFESSIONAL DEVELOPMENT
You’ll ideally have:
- A degree, higher-level apprenticeship or equivalent professional experience in cyber security, information technology, computer science or a related discipline
- Relevant industry certification such as CompTIA Security+, Microsoft Security Operations Analyst (SC-200) or equivalent demonstrable competence
- Current knowledge/training in cyber incident response, security monitoring, vulnerability management and identity & access management
- A commitment to ongoing professional development and keeping up to date with emerging threats, technologies and security practices
Please apply!
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Administration Officer
Customer Service Christmas Temps
Public Health Engineer