Senior Security Architect

developrec
Greater London, UK
3 days ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£110,000.0
Working hours
Regular working hours

Tech stack

Active Directory Domain Controllers Application Programming Interfaces (APIs) Amazon Web Services Cyber Security Linux Intrusion Detection and Prevention Python (Programming Language) Microsoft Security Essentials Windows Servers Windows PowerShell Cloud Services
+11 more
Kusto Query Language Runbook Security Information and Event Management Syslog Data Logging Scripting Cybercrime Microsoft Sentinel Network Server SentinelOne Expertise Api Management

Job description

An established organisation is seeking a Senior Security Engineer to help shape and enhance the security posture of the environments it supports. This role operates at the intersection of deep technical expertise, advisory ownership, and real-world security impact.

The successful candidate will work closely with customers, engineers, and operational security teams to deliver meaningful improvements across identity, detection engineering, endpoint security, and cloud security posture. This is a hands-on role involving the design and implementation of modern security architectures, solving complex technical challenges, and acting as a trusted technical partner., Technical Delivery

  • Lead technical discussions with customers, guiding architecture, design decisions, and best practice implementations.
  • Own the end-to-end delivery of security solutions.
  • Design and implement detections, automation workflows, and runbooks.
  • Conduct technical assessments across identity, endpoint, cloud posture, logging, and security operations.
  • Develop, optimise, and tune KQL queries for detection engineering and threat hunting.
  • Review and enhance security configurations across cloud and SIEM/SOAR platforms.
  • Manage engagements through architecture, deployment, tuning, documentation, and customer enablement.
  • Identify security gaps and recommend improvements across logging, identity, endpoint hardening, cloud posture, and threat detection.
  • Understand how endpoints, servers, domain controllers, and cloud workloads operate, and how security controls integrate with them.
  • Support remediation of misconfigurations and optimisation of security deployments.
  • Leverage scripting, APIs, and automation to streamline repeatable tasks.
  • Integrate firewalls, EDR platforms, logging pipelines, and SIEM/SOAR tooling.
  • Act as a trusted technical advisor to security and engineering stakeholders.
  • Communicate complex technical concepts clearly to both technical and non-technical audiences.
  • Translate customer requirements into actionable technical plans and deliverables.
  • Collaborate with internal engineering, SOC, and platform teams to improve processes and share insights.
  • Contribute to knowledge articles, design documentation, runbooks, and reusable delivery patterns.

Requirements

  • Microsoft Sentinel

Experience with alternative modern security platforms such as SentinelOne or CrowdStrike is advantageous.

  • Exposure to AWS or GCP (desirable)

Platforms & Infrastructure:

  • Active Directory / Entra hybrid identity
  • Windows Server and Linux

Tooling & Automation:

  • KQL
  • PowerShell
  • API integrations
  • Automation tooling, * Strong, demonstrable experience across the Microsoft security ecosystem.
  • Solid understanding of identity and endpoint security fundamentals.
  • Proven experience writing and tuning detection logic (e.g., KQL) for detection engineering and threat hunting scenarios.
  • Excellent communication and customer-facing skills, with the ability to lead discussions and influence outcomes.
  • Ability to work autonomously, solve complex problems, and deliver high-quality technical solutions.
  • Automation experience (PowerShell, Python, API integrations) and/or systems administration background.
  • Familiarity with security frameworks and incident response methodologies.
  • Experience working with logging pipelines (e.g., AMA, Syslog, Cribl, SIEM tooling).
  • Exposure to non-Microsoft security platforms such as CrowdStrike, SentinelOne, or Tenable.
  • Experience producing architecture documents, diagrams, and technical design proposals.
  • Background in an MSSP, consultancy, or customer-facing engineering environment., * Ownership of technical direction across engagements with the ability to influence customer security posture.
  • A blend of architecture, engineering, advisory, and hands-on implementation work.
  • Exposure to a diverse range of environments, threat models, and operational challenges.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:32 min

Structuring automated incident workflows between runbooks and raw models

Aram Hakobyan Aram Hakobyan +1 · World Congress 2026 Europe

2:30 min

Discovering and instrumenting services using systemd process enumeration

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

Videos

See all

Related articles

See all