Cyber Defence Network Engineer at Grant Thornton UK LLP | GB | Rezi

Cyber Defence Network Engineer at Grant Thornton UK LLP

Cyber Defence Network Engineer

Grant Thornton UK LLP · GB

Today

Cyber Defence Network Engineer

Grant Thornton UK LLP · GB

13 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Cyber Defence Network Engineer role.

Rezi rewrites your resume against Grant Thornton UK LLP's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Cyber Defence Network Engineer posting at Grant Thornton UK LLP — free, in seconds.

About the Role

As a Network Engineer within the Cyber Defence Centre, you will deliver the containment and recovery phases of live client incidents, and work on assessment, hardening and implementation engagements between them. You will be one of the people clients rely on to shut an attacker out of their estate and then help make sure it does not happen again.

Responsibilities

  • Deliver the containment and recovery phases of live client security incidents, including ransomware, business email compromise and perimeter device exploitation.
  • Isolate affected systems and accounts, restrict compromised identities, close off attacker access routes, and prevent further spread across the estate.
  • Preserve logs and evidence for the forensic investigation team, and work alongside them as the investigation develops.
  • Support client recovery, including rebuild and restoration sequencing driven by business priority, and ensure known weaknesses are not reintroduced.
  • Implement remediation and hardening work identified through the incident, where clients engage us to deliver it.
  • Work to the NIST Cyber Security Framework and incident response lifecycle, with CIS Benchmarks used for technical control recommendations.
  • Perform security reviews and configuration hardening across Microsoft 365 and Entra ID, Microsoft Azure, Amazon Web Services, on-premise Active Directory, and perimeter firewall estates.
  • Conduct firewall security assessments across multiple vendor platforms: rule base review, management plane exposure, VPN and remote access configuration, IPS/IDS posture, logging, and firmware currency.
  • Assess cloud configuration against CIS Benchmarks and NIST using tooling including Prowler, ScubaGear and PingCastle, and turn technical findings into prioritised, business-contextualised remediation plans.
  • Review third-party software, cloud applications and SaaS platforms as part of supplier and technology assurance work.
  • Support client compliance and assurance requirements including GDPR, Cyber Essentials Plus and PCI DSS.
  • Design and implement security solutions in client environments, from discovery and requirements gathering through build, testing, rollout and handover.
  • Work as part of the delivery team on a Zero Trust access programme built on Netskope One SASE, covering Secure Web Gateway, CASB (inline and API), Private Access (ZTNA) and Data Loss Prevention, integrated with Microsoft Entra ID and endpoint management.
  • Design Microsoft 365 conditional access policy sets, including MFA enforcement, legacy authentication blocking, device compliance conditions, geolocation restriction, and Privileged Identity Management for just-in-time privileged access.
  • Design network segmentation across cloud and on-premise environments: Azure Network Security Groups and subnet-level control, VLAN segregation, DMZ isolation, and layer 2 / layer 3 access control.
  • Design data classification and DLP policy, working with client data and business process owners to define label sets and handling outcomes, and validating policy behaviour in simulation before enforcement.
  • Produce security architecture artefacts, hardening standards, deployment guides, operating procedures and SOC playbooks so client teams can operate and extend what has been built.

Requirements

  • Background in network engineering with demonstrable experience of applying it to security outcomes.
  • Ideally 36 months in a security-focused role.
  • Must hold, or be actively working towards, the Netskope Certified Cloud Security Integrator (NCCSI).
  • Networking: LAN/WAN, VLAN segmentation, layer 2 / layer 3 access control, routing and switching, DMZ architecture, DNS and DHCP.
  • A background as a network engineer prior to moving into security.
  • Network security: Cisco (including Firepower), Palo Alto, FortiGate, SonicWall, Check Point, WatchGuard, Sophos, Zyxel and F5.
  • Firewall policy design and review, IPS/IDS, site-to-site and remote access VPN, and SSL/TLS inspection.
  • SASE and Zero Trust: Netskope One, Secure Web Gateway, CASB, Private Access (ZTNA) and DLP.
  • Client deployment, steering configuration, tenant configuration and troubleshooting.
  • Cloud: Microsoft Azure (NSGs, Azure Firewall, Azure Policy, Defender for Cloud), Microsoft 365 and Entra ID (conditional access, PIM, Entra Connect), AWS and Oracle Cloud.
  • Terraform for infrastructure as code.
  • Endpoint and detection: CrowdStrike Falcon (EDR, NG-SIEM, LogScale).
  • Identity: Active Directory, Entra ID, Group Policy, RBAC and privileged access.
  • Frameworks: NIST CSF and NIST 800-53, CIS Benchmarks, and ISO 27001.
  • Clear and confident communicator with strong written and verbal skills, particularly in high-pressure scenarios.
  • Able to translate technical detail for non-technical audiences, including clients, vendors and senior stakeholders.
  • Able to analyse complex environments and data, identify patterns and make evidence-based decisions.
  • Strong troubleshooting skills and the ability to develop solutions quickly and effectively during active incidents.
  • Comfortable working closely with DFIR, SOC, Cyber Advisory and client technical teams.
  • Able to embrace and manage change effectively, continuously developing skills to meet the demands of an evolving threat landscape.
  • Able to prioritise effectively while managing multiple engagements and ensuring SLAs, KPIs and client deadlines are met.
  • Careful and precise when making changes in live client environments, with high-quality, accurate documentation of every action taken.

Skills

  • Network Engineering
  • Security Outcomes
  • Netskope Certified Cloud Security Integrator (NCCSI)
  • LAN/WAN
  • VLAN segmentation
  • Layer 2 / Layer 3 access control
  • Routing and switching
  • DMZ architecture
  • DNS
  • DHCP
  • Cisco (Firepower)
  • Palo Alto
  • FortiGate
  • SonicWall
  • Check Point
  • WatchGuard
  • Sophos
  • Zyxel
  • F5
  • Firewall policy design and review
  • IPS/IDS
  • Site-to-site VPN
  • Remote access VPN
  • SSL/TLS inspection
  • Netskope One
  • Secure Web Gateway
  • CASB
  • Private Access (ZTNA)
  • DLP
  • Microsoft Azure
  • NSGs
  • Azure Firewall
  • Azure Policy
  • Defender for Cloud
  • Microsoft 365
  • Entra ID
  • Conditional access
  • PIM
  • Entra Connect
  • AWS
  • Oracle Cloud
  • Terraform
  • CrowdStrike Falcon
  • EDR
  • NG-SIEM
  • LogScale
  • Active Directory
  • Group Policy
  • RBAC
  • Privileged access
  • NIST CSF
  • NIST 800-53
  • CIS Benchmarks
  • ISO 27001
  • Communication
  • Analytical thinking
  • Problem solving
  • Teamwork
  • Collaboration
  • Adaptability
  • Time management
  • Attention to detail

Location

  • UK

Work Type

  • Full-time

Experience Level

  • Experienced

Education Level

  • Netskope Certified Cloud Security Integrator (NCCSI)
  • Cisco Certified Network Associate (CCNA)
  • Cisco Certified Entry Networking Technician (CCENT)
  • AWS Certified Cloud Practitioner
  • Microsoft Certified: Azure Fundamentals (AZ-900)
  • Microsoft Certified: Security, Compliance and Identity Fundamentals (SC-900)
  • Oracle Cloud Infrastructure Foundations Associate
  • Microsoft Certified Technology Specialist (MCTS)
  • ITIL Foundation v3

About the Company

  • At Grant Thornton we do things differently - looking to the future, driving ambitious growth and pioneering positive change in our industry. Providing audit, tax and advisory services, we empower clients through strategic insight, curiosity, and genuine partnership. And we empower our people with real opportunity, an inclusive culture and work life balance. A true alternative.
  • With over 5,000 people in the UK, and a presence in 150 global markets, we're on an ambitious journey, from great to exceptional, and we need the best people to help us achieve our potential. And with that comes the opportunity to help redefine what our industry looks like, and what you want from your career.
  • The Grant Thornton Cyber Defence Centre is an award-winning* managed security services provider operating at the forefront of cyber security, using industry-leading technologies to protect and support our clients. Alongside our SOC capability, we have cutting-edge incident response teams delivering rapid cyber breach investigations for clients through insurance panels and direct engagements, supporting organisations at their most critical moments.
  • We invest heavily in our people, offering clear progression opportunities and encouraging initiative within a collaborative, cross-functional environment with a strong team ethos. Support is always available across the SecOps, DFIR, MSS and wider cyber teams.