Cyber Security Engineer
Cyber Security Engineer – Endpoint (Intune EPM Specialist)
London - Hybrid (2 days onsite)
£435 P/D Inside IR35
BPSS clearance
We are currently seeking an experienced Cyber Security Engineer (Endpoint) to join a major enterprise security programme with a well established Insurance client. This is an exciting opportunity for a specialist with strong expertise in Microsoft Intune Endpoint Privilege Management (EPM), endpoint security, and Zero Trust principles.
You will play a key role in delivering enterprise-wide least privilege controls, removing permanent local admin rights, and implementing secure, frictionless Just-In-Time (JIT) elevation across the organisation.
Required Skills & Experience
- Hands-on experience with Microsoft Intune Endpoint Privilege Management (EPM)
- Least Privilege and Zero Trust security models
- Elevation rule creation, testing, and deployment
- Windows endpoint security hardening
- Microsoft Defender for Endpoint and Attack Surface Reduction
- Log Analytics / KQL reporting and monitoring
- Strong PowerShell scripting and automation capability
- Experience working with Microsoft Graph API
- Relevant Microsoft certifications such as: MD-102 Endpoint Administrator, MS-102 Microsoft 365 Administrator, SC-200 Security Operations Analyst or SC-300 Identity & Access Administrator
Key Responsibilities
- Lead the design, deployment, and optimisation of Microsoft Intune Endpoint Privilege Management (EPM)
- Configure and manage elevation policies, approval workflows, and automation
- Implement Just Enough Access (JEA) and Just-In-Time (JIT) elevation controls
- Analyse application privilege requirements and create appropriate elevation rules
- Remove and prevent permanent local administrator access across Windows endpoints
- Integrate EPM with Zero Trust architecture and Microsoft Defender security tooling
- Support endpoint hardening and security assessment activities
- Build monitoring dashboards and reporting using Log Analytics, KQL, Defender, and Graph API
- Collaborate with Security, Identity, Desktop, and Application teams to operationalise least privilege
- Produce documentation, runbooks, governance standards and support training activities