Cyber Defence Network Engineer

Posted 2 Days Ago
Be an Early Applicant
London, Greater London, England, GBR
In-Office
Mid level
Financial Services
The Role
Deliver live incident containment and recovery, security assessments, hardening, and managed security solution implementations for clients. Review and secure cloud, identity, firewall, endpoint, and network environments; design Zero Trust, SASE, segmentation, conditional access, and DLP solutions; preserve evidence and support forensic teams; and produce security architecture, deployment, and operational documentation.
Summary Generated by Built In
Alternatively, Grant Thornton

At Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.

With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.

Job Description:

Network Engineer, Cyber Defence Centre

Alternatively, Grant Thornton
At Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.
With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.
About us

The Grant Thornton Cyber Defence Centre is an award-winning* managed security services provider operating at the forefront of cyber security, using industry-leading technologies to protect and support our clients. Alongside our SOC capability, we have cutting-edge incident response teams delivering rapid cyber breach investigations for clients through insurance panels and direct engagements, supporting organisations at their most critical moments.

We invest heavily in our people, offering clear progression opportunities and encouraging initiative within a collaborative, cross-functional environment with a strong team ethos. Support is always available across the SecOps, DFIR, MSS and wider cyber teams.

We’re seeking an experienced Network Engineer to join our Cyber Defence Centre. This is a hands-on technical role that spans live incident response, security assessment and hardening, and the design and delivery of managed security solutions in client environments. You will be one of the people clients rely on to shut an attacker out of their estate and then help make sure it does not happen again.


A look into the role

As a Network Engineer within the Cyber Defence Centre, you will deliver the containment and recovery phases of live client incidents, and work on assessment, hardening and implementation engagements between them.

Incident response, containment and recovery

  • Delivering the containment and recovery phases of live client security incidents, including ransomware, business email compromise and perimeter device exploitation.
  • Isolating affected systems and accounts, restricting compromised identities, closing off attacker access routes, and preventing further spread across the estate.
  • Preserving logs and evidence for the forensic investigation team, and working alongside them as the investigation develops.
  • Supporting client recovery, including rebuild and restoration sequencing driven by business priority, and ensuring known weaknesses are not reintroduced.
  • Implementing the remediation and hardening work identified through the incident, where clients engage us to deliver it.
  • Working to the NIST Cyber Security Framework and incident response lifecycle, with CIS Benchmarks used for technical control recommendations.

Security assessment and hardening

  • Performing security reviews and configuration hardening across Microsoft 365 and Entra ID, Microsoft Azure, Amazon Web Services, on-premise Active Directory, and perimeter firewall estates.
  • Conducting firewall security assessments across multiple vendor platforms: rule base review, management plane exposure, VPN and remote access configuration, IPS/IDS posture, logging, and firmware currency.
  • Assessing cloud configuration against CIS Benchmarks and NIST using tooling including Prowler, ScubaGear and PingCastle, and turning technical findings into prioritised, business-contextualised remediation plans.
  • Reviewing third-party software, cloud applications and SaaS platforms as part of supplier and technology assurance work.
  • Supporting client compliance and assurance requirements including GDPR, Cyber Essentials Plus and PCI DSS.

Security solution design and implementation

  • Designing and implementing security solutions in client environments, from discovery and requirements gathering through build, testing, rollout and handover.
  • Working as part of the delivery team on a Zero Trust access programme built on Netskope One SASE, covering Secure Web Gateway, CASB (inline and API), Private Access (ZTNA) and Data Loss Prevention, integrated with Microsoft Entra ID and endpoint management.
  • Designing and deploying Microsoft 365 conditional access policy sets, including MFA enforcement, legacy authentication blocking, device compliance conditions, geolocation restriction, and Privileged Identity Management for just-in-time privileged access.
  • Designing network segmentation across cloud and on-premise environments: Azure Network Security Groups and subnet-level control, VLAN segregation, DMZ isolation, and layer 2 / layer 3 access control.
  • Designing data classification and DLP policy, working with client data and business process owners to define label sets and handling outcomes, and validating policy behaviour in simulation before enforcement.
  • Producing security architecture artefacts, hardening standards, deployment guides, operating procedures and SOC playbooks so client teams can operate and extend what you have built.

Knowing you’re right for us

Joining us as an experienced Network Engineer, the minimum criteria you’ll need is a background in network engineering with demonstrable experience of applying it to security outcomes, ideally with 36 months in a security-focused role, together with the Netskope Certified Cloud Security Integrator (NCCSI), which you must be actively working towards if you do not already hold it. You should also be able to demonstrate the following during the interview process.


Technical experience

  • Networking: LAN/WAN, VLAN segmentation, layer 2 / layer 3 access control, routing and switching, DMZ architecture, DNS and DHCP. A background as a network engineer prior to moving into security.
  • Network security: Cisco (including Firepower), Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel and F5. Firewall policy design and review, IPS/IDS, site-to-site and remote access VPN, and SSL/TLS inspection.
  • SASE and Zero Trust: Netskope One, Secure Web Gateway, CASB, Private Access (ZTNA) and DLP. Client deployment, steering configuration, tenant configuration and troubleshooting.
  • Cloud: Microsoft Azure (NSGs, Azure Firewall, Azure Policy, Defender for Cloud), Microsoft 365 and Entra ID (conditional access, PIM, Entra Connect), AWS and Oracle Cloud. Terraform for infrastructure as code.
  • Endpoint and detection: CrowdStrike Falcon (EDR, NG-SIEM, LogScale).
  • Identity: Active Directory, Entra ID, Group Policy, RBAC and privileged access.
  • Frameworks: NIST CSF and NIST 800-53, CIS Benchmarks, and ISO 27001.

Qualifications and certifications

You will hold, or be actively working towards, the Netskope Certified Cloud Security Integrator (NCCSI). This is a minimum criterion for the role.

Beyond this, you will hold, or be working towards, a relevant combination of the following:

  • Cisco Certified Network Associate (CCNA)
  • Cisco Certified Entry Networking Technician (CCENT)
  • AWS Certified Cloud Practitioner
  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900)
  • Oracle Cloud Infrastructure Foundations Associate
  • Microsoft Certified Technology Specialist (MCTS)
  • ITIL Foundation v3

Soft skills

  • Communication: A clear and confident communicator with strong written and verbal skills, particularly in high-pressure scenarios. Able to translate technical detail for non-technical audiences, including clients, vendors and senior stakeholders.
  • Analytical thinking: Able to analyse complex environments and data, identify patterns and make evidence-based decisions.
  • Problem solving: Strong troubleshooting skills and the ability to develop solutions quickly and effectively during active incidents.
  • Teamwork and collaboration: Comfortable working closely with DFIR, SOC, Cyber Advisory and client technical teams. Collaboration is essential during incident response.
  • Adaptability: Able to embrace and manage change effectively, continuously developing skills to meet the demands of an evolving threat landscape.
  • Time management: Able to prioritise effectively while managing multiple engagements and ensuring SLAs, KPIs and client deadlines are met.
  • Attention to detail: Careful and precise when making changes in live client environments, with high-quality, accurate documentation of every action taken.

#LI-SS1

Skills Required

  • Network engineering background with demonstrable experience applying networking to security outcomes
  • Approximately 36 months of experience in a security-focused role
  • Netskope Certified Cloud Security Integrator (NCCSI), or active progress toward the certification
  • LAN/WAN, VLAN segmentation, Layer 2/Layer 3 access control, routing and switching, DMZ architecture, DNS, and DHCP experience
  • Firewall security experience, including policy design and review, IPS/IDS, site-to-site and remote-access VPN, and SSL/TLS inspection
  • Experience with Cisco Firepower, Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel, or F5
  • Netskope One, Secure Web Gateway, CASB, Private Access, ZTNA, DLP, client deployment, steering configuration, tenant configuration, and troubleshooting experience
  • Microsoft Azure, Microsoft 365, Entra ID, AWS, and Oracle Cloud experience
  • Terraform infrastructure-as-code experience
  • CrowdStrike Falcon, EDR, NG-SIEM, or LogScale experience
  • Active Directory, Entra ID, Group Policy, RBAC, and privileged-access management experience
  • Knowledge of NIST CSF, NIST 800-53, CIS Benchmarks, and ISO 27001
  • Netskope Certified Cloud Security Integrator (NCCSI)
  • Relevant networking, cloud, security, infrastructure, or service-management certifications such as CCNA, CCENT, AWS Certified Cloud Practitioner, AZ-900, SC-900, Oracle Cloud Infrastructure Foundations Associate, MCTS, or ITIL Foundation v3
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: London
6,163 Employees
Year Founded: 1904

What We Do

What does business need now? An adviser that offers a different experience. A better experience. One that delivers technical expertise and a service that goes beyond. Personal, proactive, and agile. That’s Grant Thornton. We are the UK member firm of a global network that employs 58,000 people in 135 countries. We combine global scale with local insight and understanding to give you the assurance, tax, and advisory services you need to realise your ambitions. We go beyond business as usual, so you can too. We make business more personal by investing in building relationships. Whether you’re growing in one market or many, you consistently get a great service you can trust. We work at a pace that matters – yours – bringing both flexibility and rigour. We celebrate fresh thinking and diverse perspectives to bring you proactive insights and positive progress. Success tomorrow starts with making the right decisions today, which is why we match proactive insights to practical applications. Working closely with regulators, funders and standard setting bodies to help instil trust and integrity in markets. We’re committed to sustainable growth through positive progress. So, no matter the road ahead, you’re being guided by the right decisions. Going beyond to offer proactive insights, practical guidance, and positive progress. Ready to go beyond? Visit our website for insight on what we can offer you

Similar Jobs

McCain Foods Logo McCain Foods

Category Manager

Food • Retail • Agriculture • Manufacturing
In-Office
Scarborough, North Yorkshire, England, GBR
20000 Employees

McCain Foods Logo McCain Foods

Digital Process & Implementation Advisor (6month FTC)

Food • Retail • Agriculture • Manufacturing
In-Office
Scarborough, North Yorkshire, England, GBR
20000 Employees

hyperexponential Logo hyperexponential

Technical Trainer

Artificial Intelligence • Software
Hybrid
London, Greater London, England, GBR
250 Employees

Wise Logo Wise

Senior Database Engineer

Fintech • Mobile • Payments • Software • Financial Services
Hybrid
London, England, GBR
9000 Employees
88K-111K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account