Lead Cyber Security Engineer
Salary: Good salary + benefits offered
ABOUT THE COMPANY:Without question, this organisation is one of the leaders in its field. They are values driven and offer an innovative and purpose-led culture. Situated in a sought after part of town, and offering hybrid working, this is a great opportunity to join a passionate and talented team that care about what they do.
ABOUT THE ROLE:
The Lead Cyber Security Engineer reports directly to the Enterprise Architect and offers a structured development pathway into security strategy, architecture and governance, mentored directly by the Enterprise Architect. This is an exciting opportunity for someone who wants to grow beyond engineering delivery.
RESPONSIBILITIES:
Within this role, you will bring your deep hands-on expertise across Microsoft security technologies and modern endpoint detection and response platforms to take a leading role in building, hardening and defending the systems that company's people and customers rely on.
You will be responsible for engineering, operating and continuously improving the security controls that protect their digital assets, information and systems. You will own the security tooling estate end to end, engineer detections, harden endpoints, identities and cloud services, and respond to incidents to ensure the confidentiality, integrity and availability of critical data. This is a build-and-run role: you will spend most of your time hands on in the technology, turning security requirements and assessment findings into implemented, evidenced controls.
ABOUT YOU:
- Proven hands-on experience in a security engineering, security operations or infrastructure security role, with a strong build-and-run focus.
- Demonstrable experience owning an EDR or XDR platform through selection, migration and operation, for example CrowdStrike, SentinelOne or Microsoft Defender for Endpoint.
- Good Microsoft Sentinel and Microsoft Defender suite experience, including detection engineering, rule tuning and incident investigation.
- Strong knowledge of cyber security practice in a hybrid environment of on premises, SaaS and cloud services, preferably in an operations and/or incident management role.
- Experience in engineering and managing security for Azure solutions, including secure configuration of identity, network and workload services.
- Practical experience with Microsoft Entra ID conditional access, privileged identity management and access review processes.
- Experience implementing data protection tooling, including data loss prevention, sensitivity labelling and automated classification of personal or health information, for example Microsoft Purview.
- Working knowledge of zero trust network access, secure web gateway and modern secure remote access technologies.
- Experience using cyber attack methodologies and techniques such as MITRE ATT&CK, and common cyber security frameworks such as NIST 800-61 and NZISM.
- Understanding of the Essential Eight Framework and the Zero Trust Security Model.
- Knowledge of current IT security standards, practices and methods.
- Experience integrating and acting on external cyber threat intelligence within SIEM and endpoint tooling.
- Experience supporting externally delivered purple team, red team or penetration testing engagements, including findings validation and remediation.
Scripting and automation capability, for example PowerShell, Python or KQL, applied to detection, hardening or operational tooling. - Strong analytical and problem solving skills, with the ability to translate business risk into implemented technical controls.
- Experience mentoring or providing technical leadership to other IT staff.
- Familiarity with New Zealand privacy and health information obligations, including the Privacy Act 2020, is a plus.
- Relevant industry certification is a plus, for example Microsoft SC-200, AZ-500, GCIH, CISSP or CISM.
Don't miss out on this great opportunity. If you feel you're a great fit, apply online ASAP. For more information, contact Lisa Cooley on lcooley@brightspark.io