Kocho
Security Engineer

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
We are Kocho
Kocho is the original Microsoft identity-centric security partner, delivering transformational services for UK organisations. We secure every identity first - then use that foundation to strengthen security, modernise cloud and apps, and keep everything running through leading managed services, and managed security operations.
You’ll be joining a team that’s trusted by organisations to deliver at scale. As an eight-time Microsoft Partner of the Year winner and one Microsoft’s most decorated UK partners.
Our work speaks for itself:
- We’ve helped BT Group build multi-brand customer authentication at scale (including migration of 25 million accounts).
- We supported Dojo’s cloud-first identity modernisation (achieving 65% reduction in first-line support tickets and £80k+ annual savings).
- And we enabled Hallo Healthcare’s secure cloud independence (migrating 17,000 identities and 180+ applications securely to zero trust architecture with Entra).
Our head office is in the heart of London, with additional offices in Cardiff and Cape Town, providing a comfortable working environment with flexible collaboration spaces. And we’re guided by our core values: Do What’s Right, Think Greater, and Better Together.
Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences. We consider all suitable candidates regardless of their age, sex, gender reassignment, race, pregnancy and maternity, religion or belief, marital status, disability or sexual orientation. This is a mindset aligns with our company values as we understand that we are Better Together.
Here is the role:
As a Security Engineer, you will play a critical role in safeguarding our organisation, clients, and partners from cyber threats. You will apply your experience in Security Engineering or as a Senior Security Analyst to design, implement, and optimise security measures that protect systems, networks, and data from unauthorised access, attacks, and breaches. Working closely within the Security Operations team and directly with clients, you will ensure that security controls remain effective, aligned to best practice, and continuously improved. This role is primarily remote but you may be asked to come into the Cardiff or London Office at your manager’s discretion, we would expect a successful candidate to always attend when required. We anticipate this to be a couple times a month. In this role, you will deliver hands-on expertise across the Microsoft Security Stack, particularly Microsoft Defender XDR and Microsoft Sentinel. You will build, maintain, and enhance detection capabilities by deploying KQL analytical rules, developing Content Hub solutions, and tuning threat policies to ensure strong protection and high-quality signal. Your responsibilities will include managing phishing simulation campaigns, leading vulnerability scans, and producing accurate, well-structured reports with clear, actionable recommendations. You will regularly engage with clients, presenting findings and guiding them through remediation activities alongside a Cyber Security Project Manager.
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
You will also provide Incident Response support by handling escalations from the triage team, performing advanced investigations, and contributing to playbook automation using Azure Logic Apps to streamline processes and improve response consistency. Your Incident Response involvement is only from an Escalation Standpoint and you are not expected to regularly be involved in Analyst related activities. Additionally, you will audit and uplift client environments across the Microsoft 365 Security Suite, focusing on areas such as Secure Score improvements, Device Tagging, Defender policy management, Exchange configuration hardening, and other lifecycle-related security tasks. Where applicable, you may also leverage scripting or automation skills (e.g., Python, Bicep, ARM, JSON, YAML) and contribute to Logic Apps, Azure Functions, or codeless playbooks to further enhance operational efficiencies.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
This is what we need from you:
- A degree in Computer Science, Cyber Security or a related field or equivalent and demonstrable experience
- Extensive experience in Security Engineering or Senior Security Analysis
- Strong knowledge of security protocols and industry standards
- Experience with vulnerability testing and risk analysis
- SME in Microsoft Defender XDR
- Strong proven knowledge of KQL & Advanced Hunting
- Experience using common vulnerability scanning tools and interpreting their results
- Strong client-facing skills, including the ability to translate technical findings into clear, actionable recommendations. You will regularly prepare well-structured reports, present security insights to both technical and non-technical stakeholders, and provide guidance that helps clients strengthen their security posture.
Would be great if you have:
- Proficiency in certain languages, standards and assemblies/tools such as Python, Bicep, ARM, JSON, YAML
- Familiarity with Jinja2, Codeless Playbooks, Azure Functions, Azure Logic Apps
- Professional certifications such as AZ-500, SC-100, SC-200, CISSP, CEH, CYSA+
- GitHub Portfolio of solutions you’ve built
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills
Location