
Location
Barbican Support Centre, London | Hybrid Working (One office day a week)
Hours
Full-Time, 37.5 hours per week
Salary
Negotiable, competitive salary depending on experience
About the Role
At Nuffield Health, everything we give our patients, members and customers would not be possible without you. Your passion, your warmth, and your drive to make a difference are what fuel us. Whether it’s driving connected health, helping the nation, transforming experiences, or building the career you want – we give you the support to do it all. Join our journey. It starts with you.
We are seeking a skilled and enthusiastic Cyber Security Engineer to join our growing Cyber Security practice. You will work closely with Technology Service and Product Engineering teams to build and maintain a strong security posture, mitigate security risks, and foster a proactive security culture. This fixed-term contract role (until the end of 2026) offers the opportunity to contribute to the ongoing improvement of our cyber security detection and protection strategy.
Key responsibilities include contributing to security architecture decisions for new services, platforms, and third-party integrations; managing and maturing controls across Microsoft Defender products; operating and improving Azure security services; supporting infrastructure teams with secure configuration of Azure landing zones and networking; developing and maintaining security-as-code artefacts; supporting incident response playbook development and tabletop exercises; and providing guidance on security best practices within the Microsoft ecosystem.
We want you to love coming to work, feeling healthy, happy, and valued. That’s why we offer a benefits package including free gym membership, health assessments, retail discounts, and pension options. At Nuffield Health, we take care of what’s important to you.
Experience
- Proven experience in an in-house security engineering role collaborating with Technology Service and Product Engineering teams
- Proficiency with security tooling, analytics tuning, and reporting (e.g. Anti-virus, Microsoft Sentinel SIEM, endpoint XDR, cloud & network)
- Hands-on experience with Microsoft Sentinel, including KQL, analytics rules, and SOAR playbooks
- Strong working knowledge of the Microsoft Defender suite (Endpoint, Identity, Office 365, Cloud Apps, Defender for Cloud)
- Solid understanding of Azure security architecture including Entra ID, RBAC, conditional access, Azure networking, and cloud security posture
- Experience with LAN, WAN, Wireless, and Firewall technologies
- Experience working with Privileged Access Management and application control solutions
- Experience with vulnerability management in a Microsoft environment
- Ability to investigate and respond to security incidents, including log analysis and forensic triage
- Familiarity with security frameworks relevant to UK healthcare such as NIST CSF, CIS Controls, or Cyber Essentials Plus
About you
Good written and verbal communication skills with the ability to convey technical risk clearly to non-technical stakeholders. Enthusiastic and proactive with a strong commitment to maintaining and improving security posture.
Qualifications
Relevant certifications or qualifications in cyber security or related fields are advantageous but not explicitly stated. A strong practical skillset and experience are essential.
Nuffield Health














