Senior Network & Security Specialist
Licensed sponsor London, England, United Kingdom Full-time Posted 2 days ago
Company: Retail Company
Position: Senior Network & Security Specialist
Contract: Permanent
Location: London
Salary: 55,000 – 60,000 GBP + 10% Bonus
Job responsibilities:
Thank you for understanding.
#UN
Position: Senior Network & Security Specialist
Contract: Permanent
Location: London
Salary: 55,000 – 60,000 GBP + 10% Bonus
Job responsibilities:
- Network & Connectivity
- Network architecture: Own and scale EMEA network routing, switching, firewalls, VLANs, VPN and WiFi across offices, showrooms, warehouses and retail stores.
- Store & warehouse networking: Deploy, monitor and optimise general store networking and cloud-managed equipment (e.g. Cisco Meraki firewalls, switches and wireless), including firewall lifecycle planning (e.g. Meraki MX end-of-life reviews and Fortinet options).
- Secure connectivity: Manage the regional SD-WAN model (currently vendor managed) and plan our specific arrangements, including secure network bridging to 3PL/warehouse environments.
- Identity, Access & Zero Trust
- Identity & access management (Okta / Entra ID): Administer identity and access across Entra ID (Azure AD) and Okta, including SSO, MFA, application integrations and identity lifecycle, in coordination with HQ/our IAM programme.
- SASE / Netskope: Support the rollout and adoption of Netskope Private Access (SASE / zero-trust) to retire the legacy AEB-managed Cisco AnyConnect VPN for our users, working with HQ's Zero Trust and Network Infrastructure team.
- Access guardrails: Enforce network segmentation, IP whitelisting and firewall rules to align third-party and 3PL integrations with corporate cyber-security frameworks.
- Cyber-Security, Endpoint & Vulnerability Management
- Vulnerability management portfolio: Own the our vulnerability management portfolio end to end — how our security risks and vulnerabilities are identified, prioritised, remediated and reported.
- Security tooling: Operate and act on tooling across the security estate, including CrowdStrike (endpoint detection & response), Qualys (vulnerability scanning) and BitSight (external attack surface / ESAM security ratings).
- Endpoint security & patching: Enforce endpoint protection, device compliance, encryption, and patching through Microsoft Intune / MDM and coordinated patch cycles across the fleet.
- Incident response: Act as a first responder for security events (lost/stolen devices, suspicious activity, containment) and support incident notification and contractual security requirements with vendors and 3PLs (e.g. penetration testing and incident-notification clauses).
- Retail, Warehouse & Enterprise Backing
- Retail & logistics readiness: Provide network and security support for new store openings, refits and warehouse moves — secure LAN/WiFi, VLAN segmentation, RF/RFID and specialist hardware.
- SAP connectivity: Manage secure connectivity prerequisites for the SAP-centric strategy — RFC/print routing, secure paths and POS-to-ERP transaction flows.
- Global alignment: Partner with global architecture units to ensure European implementations conform to global security and network design baselines.
- Networking - 8+ years hands-on network engineering (routing, switching, firewalls, VLANs, VPN, WiFi) across multi-site.
- Security & Endpoint - Proven cyber-security experience specialised in endpoint security, vulnerability management, and patching, with practical use of CrowdStrike, Qualys and BitSight (ESAM).
- Identity & Access - Practical mastery of Okta and Entra ID (Azure AD) — SSO, MFA, app integrations, and identity lifecycle; exposure to Netskope / SASE and zero-trust models.
- Vulnerability management - Demonstrated ownership of a vulnerability management portfolio: scanning, risk prioritisation, remediation tracking, and reporting for our security vulnerabilities.
- CISM certified or actively grooming for CISM, strong grounding in security frameworks and controls.
Thank you for understanding.
#UN