Security Engineer
Cardiff • Permanent • Competitive

Security Engineer

New Easy Apply
Cardiff On-site Permanent 15 Applications
Competitive
Full-time
Posted 06 Oct 2026
Expires 05 Nov 2026

Job description

We are Kocho


Kocho is the original Microsoft identity‑centric security partner, delivering transformational services for UK organisations. We secure every identity first - then use that foundation to strengthen security, modernise cloud and apps, and keep everything running through leading managed services, and managed security operations.


You’ll be joining a team that’s trusted by organisations to deliver at scale. As an eight‑time Microsoft Partner of the Year winner and one Microsoft’s most decorated UK partners.


Our work speaks for itself:

  • We’ve helped BT Group build multi‑brand customer authentication at scale (including migration of 25 million accounts).
  • We supported Dojo’s cloud‑first identity modernisation (achieving 65% reduction in first‑line support tickets and £80k+ annual savings).
  • And we enabled Hallo Healthcare’s secure cloud independence (migrating 17,000 identities and 180+ applications securely to zero trust architecture with Entra).


Our head office is in the heart of London, with additional offices in Cardiff and Cape Town, providing a comfortable working environment with flexible collaboration spaces. And we’re guided by our core values: Do What’s Right, Think Greater, and Better Together.


Kocho is an equal opportunities employer. We make recruitment decisions based on qualifications, skill set and experiences We consider all suitable candidates regardless of their age, sex, gender reassignment, race, pregnancy and maternity, religion or belief, marital status, disability or sexual orientation. This is mindset aligns with our company values as we understand that we are Better Together.


Here is the role:


As a Security Engineer, you will be a trusted, friendly face for our clients, pairing technical know-how with the people skills to explain it clearly. Working within the Cyber Security Delivery Team and reporting to the Cyber Security Delivery Manager, you will answer client questions, research and deliver clear technical recommendations, and help clients get the very best from their Microsoft security investment.


This role is primarily remote but you may be asked to come into the Cardiff or London Office at your manager's discretion, and we would expect a successful candidate to always attend when required. We anticipate this to be a couple of times a month.

Our Delivery Team own the day-to-day client relationship. You will be their technical partner, joining client calls when needed to explain options, answer detailed questions and give confident, practical guidance. You will work across the Microsoft security stack, including Microsoft Defender XDR, Microsoft Entra, Microsoft Defender for Cloud Apps, Exchange Online and Microsoft Sentinel, with support from our senior engineers as you deepen your expertise.


You will validate every technical request that comes into the team. That means checking whether it is in scope, whether it is the right approach, and whether it aligns with best practice. Where you can, you

will configure changes in client environments yourself. Where a request needs deeper engineering, you will triage it and escalate to our senior engineering resources, who will take ownership.

We know great candidates come from many backgrounds. If you are a confident communicator who enjoys building relationships with clients, and you are still developing your technical skills, we would love to hear from you. We will invest in your training and certifications so you can grow into the role.



Your responsibilities will include:

  • Building trusted relationships with clients as their technical point of contact, supporting the Delivery Team on calls and translating technical detail into clear recommendations
  • Validating all incoming requests for scope, technical suitability and best practice before work begins
  • Configuring and tuning security controls in client environments, including Defender policies, Entra settings, Defender for Cloud Apps policies and Exchange configuration hardening
  • Triaging complex requests and escalating them to senior engineering resources with clear context, so they can take ownership quickly
  • Building, maintaining and tuning detection capabilities, including KQL analytics rules, Advanced Hunting queries and Microsoft Sentinel Content Hub solutions
  • Managing phishing simulation campaigns and supporting vulnerability scans, then interpreting the results
  • Auditing and uplifting client environments across the Microsoft 365 security suite, including Secure Score improvements, Device Tagging and other lifecycle security tasks
  • Supporting Incident Response by handling escalations and carrying out investigations alongside the wider security team
  • Delivering client reports, adding expert technical recommendations, and validating reports produced by the Delivery Team for technical accuracy before they reach the client, alongside writing clear documentation such as configuration records


Where applicable, you may also use scripting or automation skills (for example Python, Bicep, ARM, JSON or YAML) and contribute to Azure Logic Apps, Azure Functions or codeless playbooks to improve operational efficiency.


This is what we need from you:

  • A degree in Computer Science, Cyber Security or a related field or equivalent and demonstratable experience.
  • Experience in a security or technical role, such as SOC analysis, security engineering, IT support or technical delivery
  • Working knowledge of Microsoft security, including Microsoft Defender XDR, Microsoft Entra, Microsoft Defender for Cloud Apps and Exchange Online, and a drive to deepen it
  • Strong proven knowledge of KQL and Advanced Hunting
  • Experience with Microsoft Sentinel, including analytics rules and Content Hub solutions
  • Strong knowledge of security protocols and industry standards
  • An understanding of vulnerability management and risk analysis, including how to interpret the results of common scanning tools
  • Sound technical judgement, with the confidence to assess whether a request is in scope and the right approach, and to recognise when to escalate
  • Strong client-facing and people skills, including the ability to build rapport, listen well and translate technical findings into clear, actionable recommendations for both technical and non-technical stakeholders
  • Excellent written communication, with experience producing clear, well-structured technical documentation and reports
  • A curious, proactive mindset and a genuine appetite to learn and grow your technical skills

Would be great if you have:

  • Proficiency in scripting and infrastructure-as-code languages and formats such as Python, Bicep, ARM, JSON and YAML
  • Familiarity with Azure Logic Apps, Azure Functions, codeless playbooks and Jinja2
  • Professional certifications such as SC-200, SC-300, SC-401, MS-102 or AZ-500
  • A GitHub portfolio of solutions you've built
Is there something wrong with this job listing? Let us know.