Senior Security Engineer

Cybanetix
London, UK
1 day ago
Apply on www.collegerecruiter.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Domain Controllers Application Programming Interfaces (APIs) Cloud Computing Cyber Security Linux Intrusion Detection and Prevention Information Systems Security Architecture Professional Python (Programming Language) Microsoft Security Essentials Windows Servers Windows PowerShell Cloud Services
+10 more
Kusto Query Language Security Information and Event Management Syslog Data Logging Sysadmin Firewalls (Computer Science) Information Technology Network Server SentinelOne Expertise Api Management

Job description

Join us and help shape the security posture of the organisations we support. You will work directly with customers, engineers, and operationalsecurity teams to deliver meaningful improvements across identity, detection, endpoint security, and cloud posture.

This role is at the intersection of technical knowledge, advisory ownership, and real-world impact. You’ll be hands-on with the tools, designing and implementing modern security architectures, solving challenging problems, and acting as a trusted technical partner for our customers. Stack:

  • Exposure to other modern security stacks, such as SentinelOne or Crowdstrike is a strong advantage
  • Platforms: AD/Entra hybrid identity, Windows Server, Linux
  • Tooling: KQL, PowerShell, API usage, automation tooling

Technical responsibilities

  • Lead technical discussions with customers and guide them through architecture, design decisions, and best practice implementation.
  • Own the delivery of security solutions.
  • Design and implement detection, automation, and runbooks.
  • Conduct technical assessments across identity, endpoint, cloud posture, logging, and security operations.
  • Build and optimise KQL queries, detections and hunting queries.
  • Review security configurations across Cloud and SIEM/SOAR platforms.
  • Work end-to-end through architecture, deployment, tuning, documentation, and customer enablement.
  • Identify gaps and recommend improvements across logging, identity, endpoint hardening, cloud posture, and threat detection.
  • Understand how endpoints, servers, domain controllers, and cloud workloads operate and how security tools plug into them.
  • Work with customers to remediate misconfigurations, optimise deployments, and improve operational resilience.
  • Use scripting, APIs, or automation tooling to streamline repeatable tasks.
  • Support integration work across firewalls, EDR, logging pipelines, and SIEM/SOAR tooling.
  • Act as a trusted technical advisor for security and engineering stakeholders.
  • Communicate complex technical concepts clearly to both technical and non-technical audiences.
  • Build strong relationships with customers based on clarity, competence, and follow-through.
  • Translate customer needs into actionable technical plans and deliverables.
  • Work closely with internal teams (engineering, SOC, platform) to improve processes and share insights.
  • Contribute to knowledge articles, runbooks, design documentation, and repeatable delivery patterns., * The opportunity to own technical direction on engagements and influence customer security posture.
  • A role that blends architecture, engineering, advisory, and hands-on implementation using the best and brightest security technologies.
  • Learn and grow via exposure to a wide variety of environments, threat models, and operational challenges.
  • The chance to make a real difference to how defenders and security teams operate every day.

Requirements

Must have:

  • Strong, demonstrable experience across the Microsoft security stack.
  • Solid understanding of identity and endpoint security fundamentals.
  • Comfortable writing and tuning detection logic (e.g. KQL) across detective and threat-tuning scenarios.
  • Excellent communication and customer-facing skills; able to lead calls, drive discussions, and influence outcomes.
  • Ability to work autonomously, solve problems, and deliver high-quality technical work.

Nice to have:

  • Experience with automation (PowerShell, Python, API integrations) and sysadmin background.
  • Familiarity with security frameworks and incident response concepts.
  • Exposure to logging pipelines (AMA, Syslog, Cribl, SIEM tooling).
  • Working knowledge of other, non-Microsoft security stacks (CrowdStrike, SentinelOne, Tenable, etc).
  • Experience producing architecture documents, diagrams, and design proposals.
  • Background working in an MSSP, consultancy, or customer-facing engineering role.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.collegerecruiter.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

46 sec

Automating telemetry collection through robust Telegraf deployment

Mathias Palmersheim Mathias Palmersheim · Europe 2026 Virtual

2:29 min

Bypassing sysadmin restrictions across major cloud providers

Fabiano Amorim Fabiano Amorim · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all