> Markdown version of [/jobs/ext/2796930-senior-security-architect](https://www.wearedevelopers.com/jobs/ext/2796930-senior-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Architect - **Company:** developrec - **Location:** Greater London, UK (Remote available) - **Experience:** Expert - **Salary:** £110,000.0 - **Contract:** Permanent contract - **Skills:** Active Directory, Domain Controllers, Application Programming Interfaces (APIs), Amazon Web Services, Cyber Security, Linux, Intrusion Detection and Prevention, Python (Programming Language), Microsoft Security Essentials, Windows Servers, Windows PowerShell, Cloud Services, Kusto Query Language, Runbook, Security Information and Event Management, Syslog, Data Logging, Scripting, Cybercrime, Microsoft Sentinel, Network Server, SentinelOne Expertise, Api Management - **Published:** September 8, 2026 - **Apply:** https://www.collegerecruiter.com/job/2840617698-senior-security-architect ## About the Role * Microsoft Sentinel Experience with alternative modern security platforms such as SentinelOne or CrowdStrike is advantageous. * Exposure to AWS or GCP (desirable) Platforms & Infrastructure: * Active Directory / Entra hybrid identity * Windows Server and Linux Tooling & Automation: * KQL * PowerShell * API integrations * Automation tooling, * Strong, demonstrable experience across the Microsoft security ecosystem. * Solid understanding of identity and endpoint security fundamentals. * Proven experience writing and tuning detection logic (e.g., KQL) for detection engineering and threat hunting scenarios. * Excellent communication and customer-facing skills, with the ability to lead discussions and influence outcomes. * Ability to work autonomously, solve complex problems, and deliver high-quality technical solutions. * Automation experience (PowerShell, Python, API integrations) and/or systems administration background. * Familiarity with security frameworks and incident response methodologies. * Experience working with logging pipelines (e.g., AMA, Syslog, Cribl, SIEM tooling). * Exposure to non-Microsoft security platforms such as CrowdStrike, SentinelOne, or Tenable. * Experience producing architecture documents, diagrams, and technical design proposals. * Background in an MSSP, consultancy, or customer-facing engineering environment., * Ownership of technical direction across engagements with the ability to influence customer security posture. * A blend of architecture, engineering, advisory, and hands-on implementation work. * Exposure to a diverse range of environments, threat models, and operational challenges. ## Description An established organisation is seeking a Senior Security Engineer to help shape and enhance the security posture of the environments it supports. This role operates at the intersection of deep technical expertise, advisory ownership, and real-world security impact. The successful candidate will work closely with customers, engineers, and operational security teams to deliver meaningful improvements across identity, detection engineering, endpoint security, and cloud security posture. This is a hands-on role involving the design and implementation of modern security architectures, solving complex technical challenges, and acting as a trusted technical partner., Technical Delivery * Lead technical discussions with customers, guiding architecture, design decisions, and best practice implementations. * Own the end-to-end delivery of security solutions. * Design and implement detections, automation workflows, and runbooks. * Conduct technical assessments across identity, endpoint, cloud posture, logging, and security operations. * Develop, optimise, and tune KQL queries for detection engineering and threat hunting. * Review and enhance security configurations across cloud and SIEM/SOAR platforms. * Manage engagements through architecture, deployment, tuning, documentation, and customer enablement. * Identify security gaps and recommend improvements across logging, identity, endpoint hardening, cloud posture, and threat detection. * Understand how endpoints, servers, domain controllers, and cloud workloads operate, and how security controls integrate with them. * Support remediation of misconfigurations and optimisation of security deployments. * Leverage scripting, APIs, and automation to streamline repeatable tasks. * Integrate firewalls, EDR platforms, logging pipelines, and SIEM/SOAR tooling. * Act as a trusted technical advisor to security and engineering stakeholders. * Communicate complex technical concepts clearly to both technical and non-technical audiences. * Translate customer requirements into actionable technical plans and deliverables. * Collaborate with internal engineering, SOC, and platform teams to improve processes and share insights. * Contribute to knowledge articles, design documentation, runbooks, and reusable delivery patterns. ## Related Videos - [Better Together: Leveraging Your Observability Tools as a SIEM](https://www.wearedevelopers.com/videos/2118-better-together-leveraging-your-observability-tools-as-a-siem) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 191: Malware interviews, EU ❤️ Open Source and Skilled Agents](https://www.wearedevelopers.com/magazine/645-dev-digest-191-malware-interviews-eu-open-source-and-skilled-agents) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)