Security Engineering Consultant (Detection Engineering / Microsoft Sentinel)

Fazer Recruitment
London, UK
7 days ago
Apply on www.reed.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
£80,000.0 - £85,000.0
Working hours
Shift work
Job source

Tech stack

ARM Architecture Microsoft Azure Intrusion Detection and Prevention Python (Programming Language) Windows PowerShell Kusto Query Language Security Information and Event Management Management of Software Versions Microsoft Power Automate Mitre Att&ck Microsoft Sentinel Cortex XSOAR Platform
+1 more
SentinelOne Expertise

Job description

Our client, a well-established cybersecurity services provider, is growing its UK Professional Services team and needs a Senior Security Engineering Consultant to lead detection engineering and automation for its customers.

This is a hands-on, customer-facing role. You’ll design and deliver detection and response capabilities across SIEM, XDR and SOAR platforms, working alongside a dedicated SOC engineering team. You’ll also own a ā€œdetection as codeā€ approach, so detections and automations are built consistently and at scale.

What you’ll do

  • Build and tune detection rulesets in KQL (or equivalent) across SIEM and XDR platforms
  • Design use cases aligned to MITRE ATT&CK and assess coverage against customer log sources
  • Develop SOAR automations, integrations and incident response playbooks
  • Deliver detection as code pipelines with structured versioning
  • Lead customer workshops on detection strategy and SOC maturity
  • Produce clear deliverables such as detection strategies, use case catalogues and coverage assessments

Requirements

  • Strong SIEM engineering experience, ideally Microsoft Sentinel
  • Proven KQL detection writing
  • SOAR experience (Logic Apps, Cortex XSOAR or similar)
  • Python or PowerShell scripting, including API integration
  • XDR/EDR experience (Defender, CrowdStrike, Cortex or similar)
  • Azure security telemetry knowledge
  • Consultancy or customer-facing background, with excellent communication skills

Nice to have: XSIAM, SentinelOne, NDR tools (Vectra, Corelight), threat intelligence enrichment.

Benefits & conditions

  • Ā£70k-Ā£80k plus performance-based bonus
  • Hybrid working, Mon-Fri 9:00-5:30, no on-call
  • Varied customer work and exposure to real-world threats
  • Industry-leading benefits

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.reed.co.uk
Prepare application

Good distractions

Loading talks and stories from around this role…