Cyber Security Engineer
Sword is a leading provider of business technology solutions within the Energy, Public and Finance Sectors, driving transformational change within our clients. We use proven technology, specialist teams and domain expertise to build solid technical foundations across platforms, data, and business applications. We have a passion for using technology to solve business problems, working in partnership with our clients to help in achieving their goals.
We are looking for a Cyber Security Engineer to join our security team and take the lead on our security operations. Reporting to the Group CISO and working closely with IT, you will take ownership of the day-to-day running of Sword’s technical security controls, with a strong focus on Microsoft security technologies. You will play a leading role in strengthening monitoring, detection, protection, and response across the business, and in automating the work that should not be done by hand. This role suits someone with at least five years of hands-on experience, a positive can-do attitude, and the ability to take ownership, work autonomously, manage workload effectively, and deliver results.
This is a hands-on technical role with real ownership, focused on implementing, operating, and improving security controls across Sword’s environment. Working with IT and the wider security function, you will strengthen monitoring, protection, detection, response, and technical assurance through effective use of security technologies and services, and you will look for opportunities to automate. We are looking for someone who is proactive, practical, and delivery-focused, with the confidence to work independently, agree and manage priorities, and follow through with minimal supervision.
Key responsibilities include:
- Security Monitoring and Operations - Own the day-to-day security operations across Microsoft security technologies including Microsoft Sentinel, Microsoft Defender, Conditional Access, Entra ID, and related Azure security capabilities, strengthening monitoring, detection, protection, and response. You will help shape what effective monitoring looks like at Sword, working in partnership with the CISO and the wider IT team.
- Vulnerability Management and Hardening - Proactive and risk-based vulnerability management, including attack surface reduction, system hardening, remediation support, and cloud security posture improvement. You will also coordinate penetration testing and security assessments, and drive the findings through to remediation.
- Automation and Continuous Improvement - Reduce manual effort across security operations through automation, scripting, and integration. Where work is repetitive, look to automate it. Identify and implement improvements to security tooling, detection logic, control effectiveness, and operational processes through tuning, automation, and incremental engineering. This is an important part of the role.
- Security Tooling and Services - Own the security tooling estate and work closely with our external providers to make sure the services we buy deliver the outcomes we need, resolving technical issues and improving day-to-day security outcomes.
- Incident Investigation and Response - Own and run security incidents from start to finish, covering technical investigation and triage, containment, remediation, closure, and keeping the business informed as it unfolds. We are looking for someone who has personally led incidents rather than taken part in them as one of a wider team, and who turns each one into a lasting improvement in our detection and response.
- Security Awareness and Enablement - Provide the technical input behind awareness activity, simulated phishing exercises, and secure working practices, helping colleagues work safely without adding friction to their day.
- Technical Compliance and Assurance - Own the technical controls behind our certifications and assurance activity, including Cyber Essentials Plus, ISO 27001, evidence gathering, and remediation.
- Technical Risk Assessment - Lead technical security risk assessment across projects, suppliers, and internal services, identify where we are exposed, and drive practical remediation and hardening.
- Regulatory and Client Requirements - Implement, maintain, and evidence the technical controls we need to meet relevant legal, regulatory, and client security obligations.
- Supplier and Integration Security - Lead technical reviews of supplier and partner services, integrations, and access arrangements, and make sure the right controls are in place and stay in place.
This is an excellent opportunity to work with a talented team across modern security technologies, and to make a meaningful contribution to strengthening Sword’s cyber security capability. If you enjoy solving technical security challenges and want the scope to own and improve how security operations runs, we would like to hear from you.
You will need to be able to demonstrate technical experience in cyber security engineering or security operations, including direct responsibility for the day-to-day running of security tooling and incident response. Attitude matters greatly. We are looking for someone who delivers results and brings a positive, practical approach to solving problems.
You should have hands-on experience in most of the following areas, and we may explore some of them practically during the interview process:
- Microsoft security technologies, in depth. Microsoft Defender across endpoint, identity, Office 365, and cloud apps, including triage and tuning of Defender alerts. Microsoft Sentinel, including writing and tuning your own KQL queries, analytic rules, and workbooks. Microsoft Entra ID and Conditional Access policy design, testing, and troubleshooting. Microsoft Purview, Intune security controls, email security, and endpoint detection and response.
- Automation. Practical experience of removing manual effort from security operations using scripting, playbooks, Logic Apps, APIs, or similar. You should be able to talk about something you automated, what it replaced, and what it saved.
- Security control operation. Operating and improving security controls across areas such as endpoint protection, SIEM, vulnerability management, identity and access management, data protection, email security, cloud security posture, and system hardening.
- Frameworks and standards. Applying security frameworks, standards, and regulatory drivers such as NIST, ISO 27001, GDPR, and NIS2 through practical technical controls.
- Cyber Essentials Plus. Technical control implementation, evidence collection, remediation tracking, and preparation for assessment.
- Secure deployment. Supporting the secure configuration and deployment of applications, infrastructure, identities, and cloud services, working with IT teams to embed appropriate controls without slowing delivery.
- Communication. Comfortable at both ends of the conversation: technical enough to work directly with our security operations centre on detections and incidents, and clear enough to explain to senior stakeholders, up to and including the CEO, what has happened, what it means, and what we are doing about it. You will also provide practical guidance to colleagues and technical input to awareness, audit, and assurance activities.
- Background. Experience gained in a complex business environment, working with internal teams and external providers, ideally including a managed service or multi-client setting.
Qualifications and Personal Skills
- Relevant technical certifications are desirable, particularly in Microsoft security technologies such as SC-200, SC-300, SC-400, AZ-500, or similar.
- Broader security certifications are welcomed but not essential if you can demonstrate strong hands-on technical capability.
- Takes ownership, works independently when needed, and stays focused on delivering high-quality outcomes.
- Curious, proactive, and comfortable working out what needs doing rather than waiting to be asked.
- Able to manage workload effectively, prioritise sensibly, and maintain momentum in a busy technical environment.
- Communicates clearly and works well with technical and non-technical colleagues to turn security requirements into practical actions and improvements.
- Makes good use of tooling and automation to get more done, and is always looking for a better way to handle routine work.
- Keeps pace with the threat landscape out of habit rather than obligation, forms a view on what new threats and techniques mean for an organisation like ours, and raises them proactively.
At Sword, our core values and culture are based on caring about our people, investing in training and career development, and building inclusive teams where we are all encouraged to contribute to achieve success. We offer comprehensive benefits designed to support your professional development and enhance your overall quality of life. In addition to a Competitive Salary, here's what you can expect as part of our benefits package:
- Personalised Career Development: We create a development plan customised to your goals and aspirations, with a range of learning and development opportunities within a culture that encourages growth.
- Flexible working: Flexible work arrangements to support your work-life balance. We can’t promise to always be able to meet every request, however, are keen to discuss your individual preferences to make it work where we can.
- A Fantastic Benefits Package: This includes generous annual leave allowance, enhanced family friendly benefits, pension scheme, access to private health, well-being, and insurance schemes.
At Sword we are dedicated to fostering a diverse and inclusive workplace and are proud to be an equal opportunities employer, ensuring that all applicants receive fair and equal consideration for employment, regardless of whether they meet every requirement. If you don’t tick all the boxes but feel you have some of the relevant skills and experience we’re looking for, please do consider applying and highlight your transferable skills and experience. We embrace diversity in all its forms, valuing individuals regardless of age, disability, gender identity or reassignment, marital or civil partner status, pregnancy or maternity status, race, colour, nationality, ethnic or national origin, religion or belief, sex, or sexual orientation. Your perspective and potential are important to us.
If we can do anything to help make the hiring process more accessible, please let our talent acquisition team know when you apply so we can support any adjustments.