Security Engineer
Kocho Cardiff, Wales, United Kingdom
IT Services and IT Consulting · 201-500 employees
About the role
You will design, implement, and optimize security measures using the Microsoft Security Stack to protect client systems and data. Additionally, you will lead vulnerability assessments, manage incident response escalations, and provide actionable security recommendations to clients.
What they look for
Requirements
Candidates must have a degree in Computer Science or Cyber Security and extensive experience in Security Engineering or Senior Security Analysis. Strong proficiency in Microsoft Defender XDR, KQL, and vulnerability testing is essential for this role.
Full description
We are Kocho
Kocho is the original Microsoft identity‑centric security partner, delivering transformational services for UK organisations. We secure every identity first - then use that foundation to strengthen security, modernise cloud and apps, and keep everything running through leading managed services, and managed security operations.
You’ll be joining a team that’s trusted by organisations to deliver at scale. As an eight‑time Microsoft Partner of the Year winner and one Microsoft’s most decorated UK partners.
Our work speaks for itself:
- We’ve helped BT Group build multi‑brand customer authentication at scale (including migration of 25 million accounts).
- We supported Dojo’s cloud‑first identity modernisation (achieving 65% reduction in first‑line support tickets and £80k+ annual savings).
- And we enabled Hallo Healthcare’s secure cloud independence (migrating 17,000 identities and 180+ applications securely to zero trust architecture with Entra).
Our head office is in the heart of London, with additional offices in Cardiff and Cape Town, providing a comfortable working environment with flexible collaboration spaces. And we’re guided by our core values: Do What’s Right, Think Greater, and Better Together.
Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences We consider all suitable candidates regardless of their age, sex, gender reassignment, race, pregnancy and maternity, religion or belief, marital status, disability or sexual orientation. This is mindset aligns with our company values as we understand that we are Better Together.
Here is the role:
As a Security Engineer, you will play a critical role in safeguarding our organisation, clients, and partners from cyber threats. You will apply your experience in Security Engineering or as a Senior Security Analyst to design, implement, and optimise security measures that protect systems, networks, and data from unauthorised access, attacks, and breaches. Working closely within the Security Operations team and directly with clients, you will ensure that security controls remain effective, aligned to best practice, and continuously improved. This role is primarily remote but you may be asked to come into the Cardiff or London Office at your manager’s discretion, we would expect a successful candidate to always attend when required. We anticipate this to be a couple times a month. In this role, you will deliver hands-on expertise across the Microsoft Security Stack, particularly Microsoft Defender XDR and Microsoft Sentinel. You will build, maintain, and enhance detection capabilities by deploying KQL analytical rules, developing Content Hub solutions, and tuning threat policies to ensure strong protection and high-quality signal. Your responsibilities will include managing phishing simulation campaigns, leading vulnerability scans, and producing accurate, well-structured reports with clear, actionable recommendations. You will regularly engage with clients, presenting findings and guiding them through remediation activities alongside a Cyber Security Project Manager.
You will also provide Incident Response support by handling escalations from the triage team, performing advanced investigations, and contributing to playbook automation using Azure Logic Apps to streamline processes and improve response consistency. Your Incident Response involvement is only from an Escalation Standpoint and you are not expected to regularly be involved in Analyst related activities. Additionally, you will audit and uplift client environments across the Microsoft 365 Security Suite, focusing on areas such as Secure Score improvements, Device Tagging, Defender policy management, Exchange configuration hardening, and other lifecycle-related security tasks. Where applicable, you may also leverage scripting or automation skills (e.g., Python, Bicep, ARM, JSON, YAML) and contribute to Logic Apps, Azure Functions, or codeless playbooks to further enhance operational efficiencies.
This is what we need from you:
- A degree in Computer Science, Cyber Security or a related field or equivalent and demonstrable experience
- Extensive experience in Security Engineering or Senior Security Analysis
- Strong knowledge of security protocols and industry standards
- Experience with vulnerability testing and risk analysis
- SME in Microsoft Defender XDR
- Strong proven knowledge of KQL & Advanced Hunting
- Experience using common vulnerability scanning tools and interpreting their results
- Strong client‑facing skills, including the ability to translate technical findings into clear, actionable recommendations. You will regularly prepare well‑structured reports, present security insights to both technical and non‑technical stakeholders, and provide guidance that helps clients strengthen their security posture.
Would be great if you have:
- Proficiency in certain languages, standards and assemblies/tools such as Python, Bicep, ARM, JSON, YAML
- Familiarity with Jinja2, Codeless Playbooks, Azure Functions, Azure Logic Apps
- Professional certifications such as AZ-500, SC-100, SC-200, CISSP, CEH, CYSA+
- GitHub Portfolio of solutions you’ve built
Similar roles
-
Lead Security Engineer, GRC
Anduril Industries Boston, Massachusetts, United States · $166K–$253K/yr
-
Information Security Engineer (R14207)
Oportun Mexico
-
Principal Application Security Specialist
Global Relay Vancouver, British Columbia, Canada · CA$125K–CA$160K/yr
-
HSM & PKI Security Engineer
CCDS Dammam, Eastern Province, Saudi Arabia
-
Security Engineer
Warp New York, New York, United States · $230K–$290K/yr
-
Product Security Engineer
YipitData (Alternative) United States · $180K/yr