Rodeo
Get started

Penningtons Manches Cooper LLP

IT Security Engineer

Basingstoke and Deane
Posted 2 days ago
Sign up to applySee more jobs like this
Get notified of more jobs like this · No spam, ever

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Security Engineer

The Security Engineer is a core member of the Security team, responsible for protecting the organisation's technology environment through proactive security monitoring, incident response, vulnerability management, and identity & access governance. They share responsibility across all security domains, operate a named on-call rota as the primary interface to the external SOC, and provide mutual peer backup. Each Security Engineer also owns formal responsibility for Vulnerability & Compliance and Identity & Access Management as defined disciplines.

Responsibilities

Security Operations

  • Monitor the SIEM platform and security tooling daily - triaging alerts, investigating anomalies, and escalating confirmed threats.
  • Act as the named internal interface to the external SOC - receiving escalations via the on-call rota, making incident response decisions, and providing the SOC with updated detection requirements.
  • Lead incident response for confirmed security events - coordinating containment, remediation, and recovery.
  • Own and manage Defender for Endpoint / XDR and Defender for Cloud Apps - maintaining configuration, reviewing alerts, and tuning detection policies.
  • Manage SIEM rule sets - adding new detection use cases, tuning existing rules, and reviewing rule coverage.

Vulnerability & Compliance

  • Own and operate the vulnerability management programme - running regular scanning, triaging findings, and tracking remediation to SLA.
  • Manage patching governance oversight - ensuring the organisation's patch management process is followed and exceptions are documented.
  • Maintain alignment with compliance frameworks - Cyber Essentials, ISO 27001, or equivalent.
  • Own Purview Compliance - maintaining audit log policies, eDiscovery configuration, and retention policies.

Identity & Access Management

  • Own the organisation's Identity & Access Management discipline - including Entra ID, Privileged Identity Management (PIM), and access governance.
  • Monitor the joiner/mover/leaver (JML) process - ensuring accounts are provisioned, modified, and deprovisioned accurately and on time.
  • Run and manage access reviews and access certification cycles - enforcing least privilege.
  • Manage privileged accounts - ensuring all privileged access is logged, reviewed, and time-bound where possible.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

AI & Technology Governance (Security Input)

  • Review new AI tool requests from a security risk perspective - assessing data handling, access scoping, and prompt injection risk.
  • Ensure AI tools approved for use are correctly scoped and monitored; feed AI-related security findings into the risk register.

About Us

At our firm, Diversity, Equity and Inclusion is a priority and at the heart of everything we do. We actively want to attract a diverse workforce and welcome applications from everyone, from all backgrounds. We are committed to promoting an inclusive culture where everyone can be their full selves and experience being seen and heard.

We ensure that there are equal opportunities and treatment for all job applicants and employees, at all stages of the recruitment process and employment, regardless of age, gender reassignment, marriage or civil partnership, pregnancy and maternity, disability, race (including colour, nationality, ethnic or national origin), religion or belief, sex, sexual orientation, gender identity, gender expression and social background. We aim to provide adjustments for people who have a disability, long-term health condition (including mental health) or neurodiversity. If you would like to request an adjustment, please contact Sam.Austin@penningtonslaw.com.

Essential & Desirable Criteria

Essential:

  • Hands-on experience with SIEM platforms - alert triage, rule management, and investigation (Microsoft Sentinel, Splunk, or equivalent)
  • Practical experience with Defender products - Defender for Endpoint, Defender for Cloud Apps, Defender for Identity
  • Vulnerability management experience - scanning, triage, and remediation tracking
  • Identity & access management knowledge - Entra ID / Azure AD, conditional access, PIM, access reviews
  • Incident response experience - containment, investigation, and remediation in a real-world environment
  • Minimum 2–3 years in a security operations or cyber security role
  • Experience responding to real security incidents
  • Experience with vulnerability management in an enterprise environment
  • Track record of working with IAM systems in a governance or operational capacity
  • Vigilant and detail-oriented - security threats are often subtle and require sustained attention
  • Calm and structured under pressure - able to follow an incident response process during a live security event
  • Collaborative with the Cloud Platform Specialist - understands that security and platform administration are interdependent
  • Communicates security risk clearly - translates technical findings into risk language the business can understand
  • Takes ownership - does not wait to be told to act when a threat is identified

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable:

  • Security certifications: SC-200, CompTIA Security+, CySA+, CEH, or equivalent
  • Experience with Purview Compliance workloads (eDiscovery, audit logs, retention)
  • Familiarity with ISO 27001, Cyber Essentials Plus, or NIST CSF
  • Experience working with or managing an external SOC relationship
  • Experience in a peer-model security team or SOC environment
  • Exposure to a regulated industry with compliance requirements
  • Interest in emerging threats and staying current with the security landscape
Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Location

Basingstoke RG21 4FF, UK

Sign up to applySee more jobs like this