Security Engineer - Microsoft Sentinel & Defender XDR (Various levels)

Netbuilder
London, UK
9 days ago
Apply on uk.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Intrusion Detection and Prevention Python (Programming Language) Microsoft Security Essentials Windows PowerShell Kusto Query Language Security Log Data Logging Scripting Data Ingestion Mitre Att&ck Microsoft InTune
+3 more
Cybercrime Microsoft Sentinel Unified Endpoint Management

Job description

We’re hiring for experienced Security Engineers (various levels) to join our Security and Observability practice, working across a range of global client environments.

You’ll be responsible for developing and enhancing detection capabilities across modern Microsoft security platforms, using Microsoft Sentinel, Defender XDR and KQL to develop, test and optimise effective detection logic.

The roles combine hands-on engineering with problem-solving and collaboration. You’ll work with security teams to identify gaps, investigate detection challenges, improve existing use cases and develop new capabilities in response to changing threats and operational requirements.

If you enjoy getting into the detail of security data, writing detection logic and continuously finding ways to make detection capabilities more effective, we’d like to hear from you.

What you’ll be doing:

  • Develop, test and maintain detection rules across Microsoft Sentinel and Defender XDR
  • Write and optimise KQL queries to identify suspicious activity and security events
  • Analyse telemetry and investigate gaps in data quality, coverage and detection capability
  • Translate threat intelligence and security requirements into practical detection use cases
  • Work with SOC, Threat Hunting and Incident Response teams to improve detection outcomes
  • Use PowerShell or Python to automate repetitive tasks and enhance detection workflows
  • Contribute to the ongoing development of detection engineering standards and best practices

Requirements

  • Experience in Detection Engineering, Security Engineering, SOC Engineering, Threat Detection or a related cybersecurity role
  • Hands-on experience with Microsoft Sentinel and Microsoft Defender XDR and Endpoint configuration via Intune
  • Strong understanding of Security log pipelines and log ingestion technology (ideally Cribl)
  • Experience tuning detections, reducing false positives and improving detection coverage
  • Experience using KQL and scripting (PowerShell or Python)
  • Good understanding of threat detection methodologies, including MITRE ATT&CK
  • Working knowledge of security logging configuration
  • Ability to work collaboratively across cyber security, technology and operational teams
  • A proactive mindset, ability to communicate effectively, comfortable with self-directed and collaborative working
  • Experience working in a client-facing, consulting or managed services environment would be advantageous

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on uk.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

4:34 min

Motivational categories behind modern cybercriminal activities

Mauro Verderosa · LIVE

11:18 min

Addressing audience questions on security and microservice architectures

Reinhard Kugler · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

1:20 min

Identifying multi-disciplinary talent for developer experience engineering roles

Hazal Mestci +1 · Coffee With Developers

Videos

See all

Related articles

See all