Senior Security Engineering Consultant
Infosec
Southampton, UK
9 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£80,000.0
Working hours
Regular working hours
Job source
Tech stack
Artificial Intelligence
ARM Architecture
Microsoft Azure
Cloud Computing Security
Query Languages
Intrusion Detection and Prevention
Python (Programming Language)
Windows PowerShell
Kusto Query Language
Security Information and Event Management
Management of Software Versions
Data Logging
+9 more
Scripting
Cloud Platform System
Microsoft Power Automate
Mitre Att&ck
Cyber Threat Analysis
Microsoft Sentinel
Cortex XSOAR Platform
Api Design
SentinelOne Expertise
Job description
- Design and deliver detection rulesets across SIEM and XDR platforms
- Develop and tune detection logic using KQL or equivalent query languages
- Design detection use cases aligned to MITRE ATT&CK and real-world attack techniques
- Map customer log sources to detection use cases to assess coverage and identify gaps
- Design and implement SOAR automations, integrations and response workflows
- Develop and document customer incident response playbooks aligned to detection outputs
- Translate threat intelligence and operational learnings into improved detections and automations
- Deliver detection as code pipelines, including structured use case development and versioning approaches
- Produce clear technical and customer-facing deliverables, including detection strategies, use case catalogues and coverage assessments
- Work directly with customers as a trusted technical consultant
- Lead workshops covering detection engineering, use case design and SOC maturity
- Guide customers on improving detection coverage and aligning to MITRE ATT&CK
- Clearly explain detection strategies, gaps and recommendations to both technical and non-technical stakeholders
- Work closely with platform onboarding and engineering teams to ensure smooth integration of delivered detections and automations
- Support SOC teams by ensuring delivered outputs are practical, usable and aligned to operational workflows
- Contribute to the continuous evolution of detection use cases, playbooks and automation patterns
- Support development of reusable detection content and delivery standards
- Contribute to lab work, testing and validation of detection approaches
- Identify gaps in telemetry, logging and enrichment, and provide recommendations to strengthen detection outcomes, * SIEM and XDR platforms, including Microsoft Sentinel, Microsoft Defender, Palo Alto XSIAM or XDR, CrowdStrike and SentinelOne
- SOAR development, including automation and playbook design using platforms such as Palo Alto XSOAR or similar
- Scripting and integration using Python, PowerShell or similar, including API-driven automation
- Detection engineering aligned to MITRE ATT&CK, including use case design, ruleset development and coverage assessment
- Log source mapping and normalisation to support detection use cases
- Network Detection and Response technologies such as Vectra AI, Corelight or similar
- Cloud security and telemetry, particularly within Azure environments
- Threat intelligence integration and enrichment to support detection and response
- Development of customer playbooks and response workflows aligned to SOC operations
- General awareness of emerging technologies, including AI-driven security tooling and their application within detection and response
Job Specifics:
- Location: This is a hybrid role, primarily remote but with a requirement of ad-hoc travel to customer sites and attend the Basingstoke office as required to support delivery, workshops and engagements.
- Hours: Full-time, Monday - Friday, 9:00am - 5:30pm. There is no on-call requirement for this position.
Requirements
- Strong hands-on experience with SIEM engineering, including developing and tuning detection rules, with Microsoft Sentinel preferred
- Experience writing detection logic using KQL or similar query languages
- Proven experience designing and implementing SOAR automations and playbooks such as Logic Apps, Cortex XSOAR or similar
- Scripting and automation capability using Python, PowerShell or similar, including working with APIs
- Experience designing detection use cases aligned to MITRE ATT&CK
- Strong understanding of detection coverage and how log sources map to the attack lifecycle
- Experience with XDR or EDR platforms such as Microsoft Defender, CrowdStrike or Cortex
- Understanding of cloud environments, particularly Azure, and associated security telemetry
- Experience working in customer-facing or consultancy roles
- Strong communication skills, with the ability to explain technical concepts clearly
Benefits & conditions
- Salary up to £80,000
- Performance-based bonuses
- Industry-leading benefits
- A collaborative engineering environment
- Exposure to real-world threats and modern detection approaches
- Opportunity to shape Security Operations capabilities
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.collegerecruiter.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
8 months ago
AJ
Austin Joy
What Are The Top Skills Required For Azure Developers?
over 4 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
Understanding and Mitigating Common Web Vulnerabilities
over 1 year ago
LM
Luis Minvielle
Why Upskilling And Reskilling is Important For Developers
over 2 years ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
about 2 years ago