Harvey Nash
IT Security Operations Engineer (Infrastructure)

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
Role: IT Security Operations Engineer (Infrastructure)
Location: Birmingham - Hybrid
Salary: £55,000
I’m looking for an IT Security Operations Engineer to join a Digital & Technology team and help protect technology, information and services from evolving cyber threats.
This is a hands-on security operations role focused on security monitoring, incident response, security tooling, vulnerability management, identity and access management, governance and continuous improvement.
The Role
You’ll help keep systems secure, resilient and available, working closely with colleagues across IT and external security partners.
Security Monitoring & Incident Response
- Monitor security alerts across user devices, networks, cloud services and business systems
- Investigate suspicious activity, phishing emails, malware and compromised accounts
- Triage and investigate security incidents
- Take appropriate action to contain incidents and coordinate recovery with relevant IT teams
- Escalate serious incidents where required
- Maintain clear and accurate investigation and incident records
Security Tools & Controls
- Manage and maintain security tools including SIEM, Microsoft Defender, endpoint protection, email security and vulnerability scanning
- Review Microsoft 365, Azure and Entra ID security alerts and configurations
- Maintain security detection rules, dashboards and automated responses
- Support firewall, VPN, web filtering and wider network security controls
- Help ensure security tools and controls remain effective and appropriately configured
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
Vulnerability & Access Management
- Identify, assess and track system vulnerabilities and security weaknesses
- Work with technical teams to ensure security updates and remediation actions are completed
- Review privileged accounts, third-party access and inactive accounts
- Investigate unusual sign-in activity
- Support secure access controls and authentication processes
- Contribute to effective MFA and identity security practices
Governance, Reporting & Documentation
- Produce regular operational security reports, risk updates and incident summaries
- Maintain security procedures, incident response plans and technical documentation
- Support audits, compliance checks and evidence gathering
- Contribute to the development and maintenance of security policies and standards
Advice & Continuous Improvement
- Provide practical cyber security advice to employees and IT colleagues
- Support security awareness and phishing education activities
- Monitor emerging threats and assess their potential impact
- Recommend improvements to security tools, processes and configurations
- Liaise with security suppliers and managed service providers where required
- Contribute to the ongoing improvement of the organisation’s cyber security posture
What We’re Looking For
We’re looking for someone with practical experience in cyber security operations, infrastructure security or a comparable technical role.
You’ll have experience of:
- Monitoring and investigating security alerts
- Investigating phishing, malware, compromised accounts and suspicious activity
- Using and maintaining SIEM, endpoint protection, email security and vulnerability-management tools
- Working with Microsoft 365, Azure and Entra ID security controls, alerts and identity-management capabilities
- Incident response, including triage, containment, escalation, recovery and accurate record keeping
- Vulnerability remediation and managing security weaknesses
- Access controls, privileged accounts, MFA and secure authentication practices
- Network security controls including firewalls, VPNs and web filtering
- Maintaining security documentation and producing clear operational reports
- Supporting audits, compliance activity and evidence gathering
- Assessing cyber risk and providing practical technical advice
- Working effectively with internal IT teams and external security providers


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Qualifications & Professional Development
You’ll ideally have:
- A degree, higher-level apprenticeship or equivalent professional experience in cyber security, information technology, computer science or a related discipline
- Relevant industry certification such as CompTIA Security+, Microsoft Security Operations Analyst (SC-200) or equivalent demonstrable competence
- Current knowledge/training in cyber incident response, security monitoring, vulnerability management and identity & access management
- A commitment to ongoing professional development and keeping up to date with emerging threats, technologies and security practices
Please apply!
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London