Rodeo
Get started

Grant Thornton UK LLP

Cyber Defence Network Engineer

London
Posted about 20 hours ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Alternatively, Grant Thornton

At Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.

With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.

Job Description:

Network Engineer, Cyber Defence Centre

At Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.

With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.

About us

The Grant Thornton Cyber Defence Centre is an award-winning* managed security services provider operating at the forefront of cyber security, using industry-leading technologies to protect and support our clients. Alongside our SOC capability, we have cutting-edge incident response teams delivering rapid cyber breach investigations for clients through insurance panels and direct engagements, supporting organisations at their most critical moments.

We invest heavily in our people, offering clear progression opportunities and encouraging initiative within a collaborative, cross-functional environment with a strong team ethos. Support is always available across the SecOps, DFIR, MSS and wider cyber teams.

We’re seeking an experienced Network Engineer to join our Cyber Defence Centre. This is a hands-on technical role that spans live incident response, security assessment and hardening, and the design and delivery of managed security solutions in client environments. You will be one of the people clients rely on to shut an attacker out of their estate and then help make sure it does not happen again.

A look into the role

As a Network Engineer within the Cyber Defence Centre, you will deliver the containment and recovery phases of live client incidents, and work on assessment, hardening and implementation engagements between them.

Incident response, containment and recovery

  • Delivering the containment and recovery phases of live client security incidents, including ransomware, business email compromise and perimeter device exploitation.
  • Isolating affected systems and accounts, restricting compromised identities, closing off attacker access routes, and preventing further spread across the estate.
  • Preserving logs and evidence for the forensic investigation team, and working alongside them as the investigation develops.
  • Supporting client recovery, including rebuild and restoration sequencing driven by business priority, and ensuring known weaknesses are not reintroduced.
  • Implementing the remediation and hardening work identified through the incident, where clients engage us to deliver it.
  • Working to the NIST Cyber Security Framework and incident response lifecycle, with CIS Benchmarks used for technical control recommendations.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Security assessment and hardening

  • Performing security reviews and configuration hardening across Microsoft 365 and Entra ID, Microsoft Azure, Amazon Web Services, on-premise Active Directory, and perimeter firewall estates.
  • Conducting firewall security assessments across multiple vendor platforms: rule base review, management plane exposure, VPN and remote access configuration, IPS/IDS posture, logging, and firmware currency.
  • Assessing cloud configuration against CIS Benchmarks and NIST using tooling including Prowler, ScubaGear and PingCastle, and turning technical findings into prioritised, business-contextualised remediation plans.
  • Reviewing third-party software, cloud applications and SaaS platforms as part of supplier and technology assurance work.
  • Supporting client compliance and assurance requirements including GDPR, Cyber Essentials Plus and PCI DSS.

Security solution design and implementation

  • Designing and implementing security solutions in client environments, from discovery and requirements gathering through build, testing, rollout and handover.
  • Working as part of the delivery team on a Zero Trust access programme built on Netskope One SASE, covering Secure Web Gateway, CASB (inline and API), Private Access (ZTNA) and Data Loss Prevention, integrated with Microsoft Entra ID and endpoint management.
  • Designing and deploying Microsoft 365 conditional access policy sets, including MFA enforcement, legacy authentication blocking, device compliance conditions, geolocation restriction, and Privileged Identity Management for just-in-time privileged access.
  • Designing network segmentation across cloud and on-premise environments: Azure Network Security Groups and subnet-level control, VLAN segregation, DMZ isolation, and layer 2 / layer 3 access control.
  • Designing data classification and DLP policy, working with client data and business process owners to define label sets and handling outcomes, and validating policy behaviour in simulation before enforcement.
  • Producing security architecture artefacts, hardening standards, deployment guides, operating procedures and SOC playbooks so client teams can operate and extend what you have built.

Knowing you’re right for us

Joining us as an experienced Network Engineer, the minimum criteria you’ll need is a background in network engineering with demonstrable experience of applying it to security outcomes, ideally with 36 months in a security-focused role, together with the Netskope Certified Cloud Security Integrator (NCCSI), which you must be actively working towards if you do not already hold it. You should also be able to demonstrate the following during the interview process.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Technical experience

  • Networking: LAN/WAN, VLAN segmentation, layer 2 / layer 3 access control, routing and switching, DMZ architecture, DNS and DHCP. A background as a network engineer prior to moving into security.
  • Network security: Cisco (including Firepower), Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel and F5. Firewall policy design and review, IPS/IDS, site-to-site and remote access VPN, and SSL/TLS inspection.
  • SASE and Zero Trust: Netskope One, Secure Web Gateway, CASB, Private Access (ZTNA) and DLP. Client deployment, steering configuration, tenant configuration and troubleshooting.
  • Cloud: Microsoft Azure (NSGs, Azure Firewall, Azure Policy, Defender for Cloud), Microsoft 365 and Entra ID (conditional access, PIM, Entra Connect), AWS and Oracle Cloud. Terraform for infrastructure as code.
  • Endpoint and detection: CrowdStrike Falcon (EDR, NG-SIEM, LogScale).
  • Identity: Active Directory, Entra ID, Group Policy, RBAC and privileged access.
  • Frameworks: NIST CSF and NIST 800-53, CIS Benchmarks, and ISO 27001.

Qualifications and certifications

  • You will hold, or be actively working towards, the Netskope Certified Cloud Security Integrator (NCCSI). This is a minimum criterion for the role.
  • Beyond this, you will hold, or be working towards, a relevant combination of the following:
    • Cisco Certified Network Associate (CCNA)
    • Cisco Certified Entry Networking Technician (CCENT)
    • AWS Certified Cloud Practitioner
    • Microsoft Certified: Azure Fundamentals (AZ-900)
    • Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900)
    • Oracle Cloud Infrastructure Foundations Associate
    • Microsoft Certified Technology Specialist (MCTS)
    • ITIL Foundation v3

Soft skills

  • Communication: A clear and confident communicator with strong written and verbal skills, particularly in high-pressure scenarios. Able to translate technical detail for non-technical audiences, including clients, vendors and senior stakeholders.
  • Analytical thinking: Able to analyse complex environments and data, identify patterns and make evidence-based decisions.
  • Problem solving: Strong troubleshooting skills and the ability to develop solutions quickly and effectively during active incidents.
  • Teamwork and collaboration: Comfortable working closely with DFIR, SOC, Cyber Advisory and client technical teams. Collaboration is essential during incident response.
  • Adaptability: Able to embrace and manage change effectively, continuously developing skills to meet the demands of an evolving threat landscape.
  • Time management: Able to prioritise effectively while managing multiple engagements and ensuring SLAs, KPIs and client deadlines are met.
  • Attention to detail: Careful and precise when making changes in live client environments, with high-quality, accurate documentation of every action taken.
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

London, England, United Kingdom

Sign up to applySee more jobs like this