Lead Cyber Security Engineer
About the role
Microsoft security stack | Incident response | Security project leadership
Why you would like it
- Hands-on ownership across the Microsoft security suite
- Lead incident response and key remediation work
- Shape the 2027–2029 security roadmap
- Funded learning and relevant certifications
- Hybrid working: 2 days WFH, Wednesday in-office
This is a strong move for a senior, hands-on Security Engineer who wants real influence without stepping away from the technology. You’ll help improve security posture across a 3,000-person, 40+ location national organisation where security plays a central role in daily operations.
The strategy is already in motion. Your job is to execute it well, strengthen engineering capability, lead security-centred projects, and progressively help shape what comes next through 2027, 2028 and 2029. This is a leadership-of-function role, but not a “preside over” role. You’ll be close to the platforms, the controls, the incidents, and the outcomes.
Company profile
This is a large, well-established national organisation with genuine operational scale and complexity. It is a full Microsoft environment, so strong capability across the Microsoft Security Suite is mandatory.
The business has a positive learning culture and will fund relevant professional development and certifications. You’ll work with people who value trust, clear communication and practical, tested security solutions.
The role
You will:
- Own and improve security engineering capability across Microsoft Sentinel, Microsoft Defender, Entra ID, Defender for Cloud Apps, Defender for Endpoint and Microsoft Purview
- Lead security incident response, including triage, containment, investigation, remediation, root cause analysis and post-incident reviews
- Build and tune detection logic, alerts, dashboards and response playbooks, including KQL-based queries and automation where appropriate
- Drive remediation from a Purple Team review, translating findings into clear work packages and accountable delivery
- Design and deliver a tabletop exercise programme, including scenarios, facilitation, lessons learned and action tracking
- Lead Infrastructure Engineers through security-focused project work, including identity hardening, endpoint protection, secure configuration, access controls and monitoring uplift
- Review and implement fit-for-purpose tools across the security product landscape
- Present risk, incident learnings and security strategy to executive and non-technical stakeholders in clear, practical language
- Contribute to the current roadmap while helping shape the 2027–2029 security strategy
- You’ll bring:
- Strong hands-on Security Engineering experience in complex environments
- Mandatory depth across the Microsoft Security Suite
- Experience with SIEM, EDR/XDR, identity security, endpoint controls, cloud security and email security
- Incident response experience, including investigation, containment, recovery and post-incident improvement
- Exposure to Purple Team, Red Team, penetration testing or control validation activity
- Confidence leading technical project work through engineers and wider stakeholders
- Ability to explain security requirements in plain English and build trust quickly
- A practical mindset: you care about tested controls, measurable improvement and solutions that work in the real world
If you want a senior security role with engineering depth, incident leadership and genuine strategic input, apply now. The base wage is up to $155,000 plus kiwisaaver. Sorry we can not accept anyone who require work visas now or into the future...