Join the IT Naturally Team
Work for an award-winning employer that puts people first.
We’re proud to be named Employer of the Year – two years running. We go the extra mile for our employees, so they can go the extra mile for our customers.
At IT Naturally, we’re more than just colleagues - we’re a team. We support each other like family and believe that when you invest in people, they invest back in you. That’s why we offer:
- Unlimited training budget (yes, really!)
- Private healthcare from Day 1
- A company performance-related bonus (which we’ve delivered every year!)
- See all our benefits (https://www.itnaturally.com/careers/)
As a B Corp-certified MSP, we’re changing the face of the industry by putting people and the planet first. We support 250+ seat businesses with 24/7 IT services, keeping them secure, efficient, and cost-effective.
Our employees are at the heart of everything we do, and our success is measured by customers who can ‘Enjoy not talking about IT’ because when we’re their MSP, it just works.
We’re always looking for people who bring fresh ideas, want their voices heard, and thrive in an environment where people come first.
Our inclusive workplace values diversity, equality, and inclusion, and we encourage applicants from all backgrounds to apply.
Role Overview
As a Cyber Security Engineer, you will deliver, support and continually improve IT Naturally’s internal and customer security services. You will investigate incidents, manage vulnerabilities, implement security controls and provide practical security guidance across Microsoft 365, Azure, endpoint, network and cloud environments. Working with customers, suppliers and internal teams, you will help ensure that services are secure, resilient and aligned with business, contractual and regulatory requirements.
Role Responsibilities
- Investigate, contain and resolve cyber security events and incidents, escalating where appropriate and completing root cause analysis for significant or recurring issues.
- Design, implement and maintain proportionate security controls across Microsoft 365, Azure, endpoint, network and cloud environments.
- Assess security risks arising from new services, projects and changes, and provide clear remediation advice through change and CAB processes.
- Manage vulnerability activities, including assessment, prioritisation, reporting, remediation tracking and validation.
- Ensure the maintenance of security configurations, appliances and platforms through appropriate patching, upgrades and lifecycle management.
- Create and maintain cyber security-related operating procedures, security baselines, technical standards, architecture records and customer-facing documentation.
- Support security governance and compliance activities, including risk assessments, policy development, control implementation, evidence gathering and audits for frameworks such as ISO 27001 and Cyber Essentials.
- Monitor relevant threats and emerging technologies, assess their impact on IT Naturally and its customers, and coordinate appropriate action.
- Provide trusted technical security consultancy to customers and internal teams, translating technical risks into clear, business-focused recommendations.
- Produce accurate security reports, service metrics and compliance information for internal and customer stakeholders.
- Improve repeatable security operations through automation, knowledge transfer and guidance for first- and second-line support teams.
- Contribute to the 24x7 on-call rota and respond to priority security incidents in line with agreed processes.
Role Requirements
Essential technical knowledge and experience
- Hands-on experience of security monitoring, incident investigation and vulnerability management.
- Practical knowledge of Microsoft security technologies, including Microsoft Defender XDR, Microsoft 365 security controls, Microsoft Intune and Endpoint Security.
- Experience administering endpoint detection and response platforms; CrowdStrike Falcon experience is advantageous.
- Good understanding of identity and access management, MFA, data loss prevention, encryption and advanced threat protection.
- Strong knowledge of cyber security principles and technologies, including Secure Email Gateways, DNS filtering, Secure Web Gateways, Cloud Access Security Brokers (CASB), endpoint protection, anti-virus, and related security controls.
- Knowledge of secure design principles and the ability to assess technical solutions, configurations and changes.
- Working knowledge of security frameworks and assurance activities, including ISO 27001, Cyber Essentials, CIS Controls and the NIST Cybersecurity Framework.
- Awareness of data protection, AI governance and the security risks associated with emerging technologies.
Essential professional and personal capabilities
- Ability to analyse complex security issues, evaluate urgency and business impact, and make clear, timely decisions.
- Ability to communicate technical risks and recommendations clearly to customers, colleagues and both technical and non-technical stakeholders.
- Strong written skills, with experience producing concise policies, standards, procedures, reports and governance documentation.
- A collaborative, customer-focused approach and the confidence to provide trusted security advice.
- A strong interest in cyber security, with a proactive, self-driven approach and the ability to respond dynamically and at pace to emerging threats, risks and priorities.
- A continuous improvement mindset, proactively identifying and bringing forward suggestions to improve the security service, including opportunities to use automation to increase efficiency, consistency and service quality.
- Commitment to continual learning and knowledge sharing, keeping knowledge current as cybersecurity threats, technologies and practices evolve.
- Excellent written and spoken English; German language capability is desirable.
Desirable qualifications and development
- A relevant Microsoft security certification, such as Security Operations Analyst, Identity and Access Administrator or an equivalent current certification.
- CompTIA CySA+, CISSP or another recognised cyber security qualification, or a demonstrable commitment to achieving one.
- Capability aligned to SFIA responsibility level 4, working with autonomy, influence and appropriate complexity.
Interview Process
The selection process consists of three stages:
- Initial Video Interview – a chance to discuss your experience and motivations.
- Psychometric Assessment – to help us understand your strengths and working style.
- Final Face-to-Face Interview – a formal and in-depth interview with the hiring team.
We are unable to offer sponsorship for this role.
The successful candidate will be subject to pre-employment checks, including a BPSS (Baseline Personnel Security Standard) check.
Pay: £40,000.00-£50,000.00 per year
Benefits:
- Canteen
- Casual dress
- Company pension
- Cycle to work scheme
- Free flu jabs
- Free parking
- Health & wellbeing programme
- Life insurance
- On-site parking
- Paid volunteer time
- Private medical insurance
Application question(s):
- Do you require sponsorship?
- Can you design, implement and maintain proportionate security controls across Microsoft 365, Azure, endpoint, network and cloud environments.
- Are you able to ensure the maintenance of security configurations, appliances and platforms through appropriate patching, upgrades and lifecycle management
Experience:
- Cyber Security Engineer: 3 years (required)
Work authorisation:
- United Kingdom (required)
Work Location: Hybrid remote in Peterborough