OCU is seeking a proactive and technically driven Digital Security Engineer to join our growing Cyber Security team in Preston. Reporting to the Security Operations Manager, you will play a key role in designing, implementing and continuously improving security controls that protect OCU's cloud platforms, identity services, endpoints, networks and business systems across the UK, Australia and the US.
This is a hands-on engineering role focused on hardening environments, reducing cyber risk, driving vulnerability remediation and enhancing security capabilities across the Microsoft security ecosystem. Working closely with Security Analysts, Infrastructure, Cloud, IAM and Application teams, as well as our 24/7 managed SOC partner, you will build, maintain and optimise the security controls that safeguard OCU's digital estate around the clock.
- Design, implement and maintain security controls across cloud, endpoint, network and identity environments.
- Configure and optimise Microsoft security technologies including Defender XDR, Sentinel, Entra ID, Intune and Purview.
- Engineer secure identity and access management controls, including MFA, Conditional Access and privileged access management.
- Lead technical vulnerability remediation activities, implementing hardening, patching and risk reduction measures.
- Support cyber incident response and recovery activities through hands-on engineering expertise.
- Develop security standards, automation, documentation and repeatable engineering processes.
- Collaborate with technology teams to ensure secure-by-design principles are embedded across projects and services.
You'll have experience in a Security Engineer, Cyber Security Engineer, Cloud Security Engineer or similar role, with strong knowledge of Microsoft security technologies and modern security engineering practices. You'll be passionate about continuous improvement, proactive risk reduction and delivering high-quality security outcomes in a fast-paced, multi-region environment.
Desirable certifications include AZ-500, SC-200, SC-300, MS-102 or CompTIA Security+, alongside experience with vulnerability management tools such as Qualys, Tenable or SecurityScorecard.